CVE-2026-105630
Deferred Deferred - Pending Action

Authenticated SVG Upload Leads to Stored XSS in Plane

Vulnerability report for CVE-2026-105630, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application's security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-616 The PHP application uses an old method for processing uploaded files by referencing the four global variables that are set for each file (e.g. $varname, $varname_size, $varname_name, $varname_type). These variables could be overwritten by attackers, causing the application to process unauthorized files.
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105630 is a stored Cross-Site Scripting (XSS) vulnerability in the Plane project management tool. An authenticated low-privilege workspace member, including a Guest, can upload a malicious SVG file as an attachment. When served inline with a Content-Disposition header, the SVG's embedded JavaScript executes in the application's security context, potentially leading to session theft or account takeover for users who open the link.

Detection Guidance

To detect this vulnerability, check Plane application versions for 1.3.1 or earlier. Inspect uploaded SVG attachments for embedded JavaScript or malicious payloads. Review server responses for Content-Disposition headers on SVG files. Use browser developer tools to verify if SVG files render inline with script execution capability.

Impact Analysis

This vulnerability allows an attacker with minimal privileges to compromise user sessions, including administrators, by tricking them into opening a malicious SVG file link. The attacker could steal session cookies or perform actions on behalf of the victim, leading to account takeover and potential unauthorized access to sensitive data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate GDPR's data protection requirements and HIPAA's safeguards for protected health information. The stored XSS allows attackers to steal session cookies or perform actions on behalf of users, potentially exposing personal or health data.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. Ensure all SVG attachments are served with Content-Disposition: attachment header. Block or sanitize SVG uploads if not required. Monitor for unauthorized access or suspicious activity in admin accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105630. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart