VYPR

Plane

by Plane

pypi: plane

Source repositories

CVEs (24)

  • CVE-2026-15342MedJul 21, 2026
    risk 0.00cvss 6.5epss 0.00

    Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected…

  • CVE-2026-27705MedFeb 25, 2026
    risk 0.00cvss 6.5epss 0.00

    Plane is an an open-source project management tool. Prior to version 1.2.2, the `ProjectAssetEndpoint.patch()` method in `apps/api/plane/app/views/asset/v2.py` (lines 579–593) performs a global asset lookup using only the asset ID (`pk`) via `FileAsset.objects.get(id=pk)`,…

  • CVE-2025-48070LowMay 21, 2025
    risk 0.00cvss 3.5epss 0.00

    Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such…

  • CVE-2024-47830CriOct 11, 2024
    risk 0.00cvss 9.3epss 0.01

    Plane is an open-source project management tool. Plane uses the ** wildcard support to retrieve the image from any hostname as in /web/next.config.js. This may permit an attacker to induce the server side into performing requests to unintended locations. This vulnerability is…

Page 2 of 2