CVE-2026-104977
Deferred Deferred - Pending Action

Server-Side Request Forgery in Plane Project Management Tool

Vulnerability report for CVE-2026-104977, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Server-Side Request Forgery (SSRF) vulnerability in the Plane project management tool affecting versions up to 1.3.1. It is an incomplete fix for a previous SSRF issue (CVE-2026-27706). Authenticated project members can exploit it to make the server fetch internal targets, including cloud metadata endpoints like 169.254.169.254. The server returns the response body to the attacker via link titles or favicons, enabling data exfiltration.

Detection Guidance

To detect this SSRF vulnerability in Plane, check if your instance is running a version prior to 1.4.0. Inspect network logs for unusual outbound requests to internal IPs like 169.254.169.254 or cloud metadata endpoints. Monitor for unexpected link titles or favicons containing internal data.

Impact Analysis

An attacker with authenticated access to a project could read internal server responses, including sensitive data from internal services or cloud metadata. This could lead to unauthorized access to confidential information, internal network mapping, or further exploitation of internal systems.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using affected Plane versions may face compliance violations and potential legal consequences.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. If upgrading is not possible, restrict access to authenticated project members only and block outbound requests to internal IP ranges at the network level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104977. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart