PT-2026-106036 · Plane · Plane
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
An issue exists where the endpoint "/api/workspaces/{slug}/entity-search/?query type=user mention" returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace
slug, regardless of whether the user is a member of that workspace. Additionally, the endpoint exposes ProjectMember rows. This occurs because the SearchEndpoint in apps/api/plane/app/views/search/base.py inherits from BaseAPIView and only requires authentication without verifying workspace membership.Recommendations
Update to version 1.4.0.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane