CVE-2026-104960
Deferred Deferred - Pending Action

Plane Unauthorized Asset Download in Workspace Scope

Vulnerability report for CVE-2026-104960, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same workspace, is not a member of the victim's secret project, and knows the target asset UUID can receive a 302 redirect to a signed download URL. The intended project-scoped route for the same asset correctly returns 403. Confirmed affected project-bound asset types are ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER. This bypass exposes private file content protected by the secret project boundary. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104960 is an Insecure Direct Object Reference (IDOR) vulnerability in Plane, an open-source project management tool. It allows authenticated workspace users who are not members of a secret project to access private file assets (like issue attachments or descriptions) belonging to that project by exploiting a missing project-level access check in the workspace-scoped asset download endpoint.

Detection Guidance

To detect this vulnerability, check Plane versions prior to 1.4.0. Verify if workspace-scoped asset endpoints like GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ are accessible to non-project members. Test by attempting to access project-bound assets without project membership. Use logs to identify unauthorized 302 redirects to signed URLs for ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, or PROJECT_COVER assets.

Impact Analysis

An attacker could access confidential project files (e.g., attachments, descriptions) without proper authorization. This requires the attacker to be a workspace member, not part of the secret project, and to know the asset UUID. The impact includes unauthorized data exposure but does not allow modification or deletion of files.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating GDPR (data protection) and HIPAA (health information privacy) by exposing confidential project files. Compliance may be compromised if private data is accessed without proper authorization.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Ensure all workspace members are verified and remove unauthorized users. Review asset access logs for suspicious activity. Apply strict project membership checks for all project-bound assets. Disable workspace-scoped asset endpoints if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104960. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart