PT-2026-106084 · Plane · Plane
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.4.0
Description
An issue exists in the
ProjectBulkAssetEndpoint.post endpoint within apps/api/plane/app/views/asset/v2.py where assets are retrieved using id in=asset ids and workspace slug=slug without constraining the query by the project id provided in the URL. This allows a workspace Guest to provide asset UUIDs from a different project within the same workspace and reassign the issue id, comment id, page id, draft issue id, or project id to an entity controlled by the attacker. Consequently, the system recognizes the attacker's project as the new owner and generates a presigned download URL for the hijacked file.Recommendations
Update to version 1.4.0.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane