PT-2026-106078 · Plane · Plane

·

CVE-2026-105631

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description Insufficient access control in the project management tool allows unauthorized retrieval of file assets. The endpoints 'WorkspaceFileAssetEndpoint.get' and 'WorkspaceAssetDownloadEndpoint.get' resolve FileAsset records without verifying if the workspace member belongs to the asset's project, enabling the download of assets from private projects if the asset UUID is known. Additionally, the 'EntityAssetEndpoint.get' public-anchor endpoint grants AllowAny access and limits lookups to the workspace level rather than the specific published entity or project. This allows unauthenticated users with a valid anchor and asset UUID to retrieve issue-description or comment-description assets from private or unpublished projects within that workspace.
Recommendations Update to version 1.4.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105631
GHSA-85H2-MHCC-XFMW

Affected Products

Plane