PT-2026-106078 · Plane · Plane
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
Insufficient access control in the project management tool allows unauthorized retrieval of file assets. The endpoints 'WorkspaceFileAssetEndpoint.get' and 'WorkspaceAssetDownloadEndpoint.get' resolve
FileAsset records without verifying if the workspace member belongs to the asset's project, enabling the download of assets from private projects if the asset UUID is known. Additionally, the 'EntityAssetEndpoint.get' public-anchor endpoint grants AllowAny access and limits lookups to the workspace level rather than the specific published entity or project. This allows unauthenticated users with a valid anchor and asset UUID to retrieve issue-description or comment-description assets from private or unpublished projects within that workspace.Recommendations
Update to version 1.4.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane