CVE-2026-104956
Deferred Deferred - Pending Action

Unauthenticated Field Injection in Plane Project Management Tool

Vulnerability report for CVE-2026-104956, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts group_by and sub_group_by query parameters and passes them without an allowlist to grouped paginators, where they are used as ORM field names by F(field), .values(field), .order_by(field), and Window partition_by operations. An anonymous attacker can supply arbitrary field paths that trigger an unhandled FieldError or KeyError and an HTTP 500 response, or force the ORM to resolve __-separated relational paths as a blind traversal oracle. This is the same field-name injection class addressed by earlier order_by sanitization, but that remediation left group_by and sub_group_by unvalidated. The issue does not directly disclose column values because issue_group_values() returns an empty list for unknown fields, the result projection uses a fixed required_fields list, and the subgrouped path raises KeyError before serialization. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an ORM field-name injection vulnerability in Plane, an open-source project management tool. Prior to version 1.4.0, unauthenticated users could manipulate the group_by and sub_group_by query parameters to inject arbitrary field paths into ORM operations like F(), values(), order_by(), and Window partition_by. This could cause HTTP 500 errors or enable blind relational-traversal attacks without exposing sensitive data directly.

Detection Guidance

To detect this vulnerability, check Plane software versions prior to 1.4.0. Test unauthenticated endpoints with crafted group_by and sub_group_by parameters like created_by__password to see if they trigger HTTP 500 errors or unexpected responses.

Impact Analysis

The impact includes denial of service (DoS) via crashes when invalid fields are provided, and potential database performance issues from forced relational traversals. Attackers could also use it as a blind oracle to probe database structure, though direct data exposure is limited by the application's design.

Compliance Impact

This vulnerability does not directly expose sensitive data but enables blind relational-traversal attacks and denial of service via ORM errors. While not a direct data breach, such attacks could lead to unauthorized access patterns or service disruptions, which may violate compliance requirements for data integrity and availability under standards like GDPR or HIPAA.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later. Ensure the ISSUE_GROUP_BY_ALLOWLIST is enforced in order_queryset.py and BasePaginator.paginate() to block invalid field names. Monitor for HTTP 500 errors on public endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104956. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart