VYPR

superplane

by Superplanehq

CVEs (2)

  • CVE-2026-57511Jul 28, 2026
    risk 0.00cvss epss 0.00

    SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject arbitrary SMTP headers by including CRLF sequences in the event payload title field delivered via webhook. Attackers can manipulate the unsanitized title…

  • CVE-2026-57510Jul 28, 2026
    risk 0.00cvss epss 0.00

    SuperPlane before 0.27.0 contains a broken object-level authorization vulnerability in the CanvasService gRPC handlers that allows authenticated users with viewer-level access to one organization to access resources belonging to other organizations by supplying arbitrary canvas…