PT-2026-106083 · Makeplane · Plane

·

CVE-2026-105636

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook task.py calls requests.post() without allow redirects=False and does not validate redirect targets. validate url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105636

Affected Products

Plane