CVE-2026-105628
Deferred Deferred - Pending Action

Plane OAuth Avatar URL Redirect to Internal Resource Exposure

Vulnerability report for CVE-2026-105628, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Plane, an open-source project management tool, prior to version 1.4.0. It involves the OAuth avatar synchronization feature which fetches avatar URLs from providers without validating internal IP addresses or restricting redirects. Attackers can exploit this by providing a malicious URL that redirects to an internal resource, such as a metadata endpoint. Plane then uploads the fetched internal content as a user avatar file, which is exposed through a static asset endpoint, allowing unauthorized data exfiltration.

Detection Guidance

Check Plane version with: curl -s http://your-plane-instance.com/api/version | grep version. If version is below 1.4.0, the system is vulnerable. Inspect network logs for outbound HTTP requests to internal IP ranges or metadata endpoints from Plane's backend.

Impact Analysis

If you use Plane versions 1.3.1 or earlier, an attacker with access to your internal network could exploit this to access internal resources like metadata endpoints. They could then exfiltrate sensitive data stored in Plane by retrieving it through the static asset endpoint. This could lead to unauthorized access to internal systems and persistent storage of sensitive information.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR, HIPAA, or other regulations. Exposure of internal resources or sensitive user data through exfiltration could result in data breaches, leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. If upgrading is not possible, disable OAuth avatar synchronization in Plane's configuration to prevent avatar URL fetching. Ensure your IdP (like Gitea or GitLab) does not allow attacker-controlled avatar URLs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105628. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart