Plane: 25 Vulnerabilities Disclosed Together, Ranging from Critical to High
Key findings • 25 vulnerabilities disclosed in Plane within a 2-hour window on October 5, 2026. • Critical flaws include insecure default secrets, OAuth trust issues, and weak OTP mechanisms.…

Key findings
- 25 vulnerabilities disclosed in Plane within a 2-hour window on October 5, 2026.
- Critical flaws include insecure default secrets, OAuth trust issues, and weak OTP mechanisms.
- Multiple vulnerabilities involve insecure access control, allowing unauthorized data access and actions.
- SSRF and insecure external request handling are present across several CVEs.
- All disclosed vulnerabilities are fixed in Plane version 1.4.0.
On October 5, 2026, a significant batch of 25 vulnerabilities was disclosed for Plane, an open-source project management tool. The vulnerabilities, disclosed within a two-hour window, range in severity from High to Critical, with several Critical-rated flaws carrying CVSS scores up to 9.8. These issues collectively expose users to risks including unauthorized data access, account takeovers, and system compromise.
Several vulnerabilities stem from insecure handling of secrets and authentication mechanisms. CVE-2026-105641, a Critical vulnerability with a CVSS score of 9.8, highlights the risk of fixed, publicly known default secrets (SECRET_KEY and LIVE_SERVER_SECRET_KEY) in deployment manifests if not overridden. Another Critical flaw, CVE-2026-105640 (CVSS 9.1), involves Plane trusting email addresses from Gitea and GitLab OAuth without proper verification, potentially allowing attackers to spoof user identities. The signup flow is also affected by CVE-2026-105639 (CVSS 9.8), where a user row is created without an ownership check, enabling manipulation of workspace invitations. Furthermore, CVE-2026-105638 (CVSS 9.1) points to a weak six-digit numeric OTP for magic-code email login, lacking sufficient security measures against brute-force attempts.
Access control and authorization appear to be recurring themes among the disclosed vulnerabilities. CVE-2026-105637 (CVSS 9.6) details how a workspace Guest can access assets from other projects by manipulating asset IDs. Similarly, CVE-2026-105630 (CVSS 8.7) allows even low-privilege members to upload malicious SVG files as attachments, which are then served with attacker-controlled Content-Types. CVE-2026-105632 (CVSS 8.7) describes a GraphQL mutation that permits any workspace member to add themselves to any project, including private ones, with a full Member role. CVE-2026-105629 (CVSS 7.1) enables administrators or members of one workspace to delete estimate points from another workspace due to insufficient scoping in the deletion endpoint. CVE-2026-104969 (CVSS 6.5) allows authenticated users to add issues from any workspace to a cycle they control, potentially impacting victim issues already assigned to a cycle.
Server-Side Request Forgery (SSRF) and insecure handling of external requests are also present. CVE-2026-105636 (CVSS 9.9) involves a webhook delivery task that does not properly validate redirect targets, potentially leading to SSRF. CVE-2026-104977 (CVSS 7.7), an incomplete fix for a previous SSRF vulnerability, still allows authenticated project members to target internal resources. CVE-2026-104978 (CVSS 8.2) notes that Plane validates GITEA_HOST only by its URL scheme, not by IP address, and the subsequent outbound requests do not use a validation function, opening avenues for attacks against internal services. CVE-2026-105628 (CVSS 7.6) describes an OAuth avatar synchronization flow that follows redirects without internal IP validation, enabling SSRF attacks.
Other notable vulnerabilities include CVE-2026-104979 (CVSS 8.7), which allows any authenticated user to inject arbitrary HTML into issue descriptions due to improper HTML sanitization. CVE-2026-104974 (CVSS 8.1) permits deactivated accounts to log in and silently reactivate themselves. CVE-2026-104973 (CVSS 7.6) indicates that webhook IP address validation is only performed during creation, not during delivery, potentially allowing malicious webhooks to bypass security checks. CVE-2026-104971 (CVSS 8.5) allows for cross-workspace asset duplication due to insufficient workspace limitations in asset fetching endpoints. CVE-2026-104970 (CVSS 8.1) describes an insecure instance administrator sign-up process that lacks proper concurrency controls. Finally, CVE-2026-104968 (CVSS High) allows any authenticated user to retrieve sensitive workspace member information, including display names, UUIDs, and avatar URLs, even if they are not members of the workspace.
All these vulnerabilities were fixed in Plane version 1.4.0. Users are strongly advised to update to this version immediately to mitigate the extensive security risks posed by this batch of vulnerabilities. The sheer number and severity of these flaws underscore the importance of rigorous security auditing and timely patching for the Plane project.
The following CVE IDs were referenced in this article: CVE-2026-105641, CVE-2026-105640, CVE-2026-105639, CVE-2026-105638, CVE-2026-105637, CVE-2026-105630, CVE-2026-105632, CVE-2026-105629, CVE-2026-104979, CVE-2026-104977, CVE-2026-104978, CVE-2026-105628, CVE-2026-104974, CVE-2026-104973, CVE-2026-104971, CVE-2026-104970, CVE-2026-104969, CVE-2026-104968.