PT-2026-106056 · Plane · Plane

·

CVE-2026-104977

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An authenticated project member can perform a Server-Side Request Forgery (SSRF) during the work-item link unfurling process. This allows the server to fetch internal targets selected by the attacker, such as cloud metadata at 169.254.169.254, and return the response body via the link title or favicon. SSRF is a flaw where an attacker forces a server to make requests to an unintended location.
Recommendations Update to version 1.4.0.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104977
GHSA-HHJ8-7HV6-M74R

Affected Products

Plane