PT-2026-106088 · Git+1 · Plane
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET KEY and LIVE SERVER SECRET KEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRET KEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVE SERVER SECRET KEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Plane