Plane · Plane · CVE-2026-104962
**Name of the Vulnerable Software and Affected Versions**
Plane versions prior to 1.4.0
**Description**
An issue exists where the endpoint "/api/v1/workspaces/{slug}/projects/{project id}/members/" returns the complete project-member roster, including email addresses, names, avatars, and roles. The `ProjectMemberPermission` check only verifies if the caller is an active member of any project within the workspace, failing to bind the check to the specific `project id`. As a result, any authenticated user, including those with Guest roles, can access the member list of other private projects within the same workspace by manipulating the `project id` variable in the URL.
**Recommendations**
Update to version 1.4.0.