Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Thientd

#37150of 57,628
7.7Total CVSS
Vulnerabilities · 1
PT-2026-106056
7.7
2026-10-05
Plane · Plane · CVE-2026-104977
**Name of the Vulnerable Software and Affected Versions** Plane versions prior to 1.4.0 **Description** An authenticated project member can perform a Server-Side Request Forgery (SSRF) during the work-item link unfurling process. This allows the server to fetch internal targets selected by the attacker, such as cloud metadata at 169.254.169.254, and return the response body via the link title or favicon. SSRF is a flaw where an attacker forces a server to make requests to an unintended location. **Recommendations** Update to version 1.4.0.