CVE-2026-104979
Deferred Deferred - Pending Action

Stored XSS in Plane Project Management Tool

Vulnerability report for CVE-2026-104979, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a stored cross-site scripting (XSS) vulnerability in the Plane project management tool affecting versions before 1.4.0. It allows authenticated users, even without workspace memberships, to inject malicious HTML into projects with intake enabled. The injected JavaScript can execute when a victim clicks a planted link, stealing a long-lived API token from their session.

Detection Guidance

Check Plane application version. If running version <= 1.3.1, the system is vulnerable. Inspect HTML content in intake items for malicious scripts or unusual javascript: links. Look for unauthorized API token creation events in logs.

Impact Analysis

An attacker could steal your API token, gaining full access to your workspaces. The stolen token remains valid even after logout or password changes. The attack requires you to click a malicious link, but the payload executes in your browser session, potentially compromising your account and data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. It may result in data breaches, unauthorized disclosure of personal or health information, and non-compliance with access control and integrity requirements.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Review and remove any suspicious HTML content in intake items. Monitor API token creation logs for unauthorized activity. Ensure validate_html_content is applied to all HTML fields.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104979. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart