PT-2026-106084 · Plane · Plane

·

CVE-2026-105637

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.4.0
Description An issue exists in the ProjectBulkAssetEndpoint.post endpoint within apps/api/plane/app/views/asset/v2.py where assets are retrieved using id in=asset ids and workspace slug=slug without constraining the query by the project id provided in the URL. This allows a workspace Guest to provide asset UUIDs from a different project within the same workspace and reassign the issue id, comment id, page id, draft issue id, or project id to an entity controlled by the attacker. Consequently, the system recognizes the attacker's project as the new owner and generates a presigned download URL for the hijacked file.
Recommendations Update to version 1.4.0.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105637
GHSA-R2HW-FFF3-PJWP

Affected Products

Plane