CVE-2026-105631
Deferred Deferred - Pending Action

Path Traversal in Plane Project Management Tool

Vulnerability report for CVE-2026-105631, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105631 is an authorization bypass vulnerability in Plane, an open-source project management tool. It allows workspace members to access private files from projects they are not part of by exploiting improper authorization checks in asset download endpoints. The endpoints incorrectly scope file lookups to the workspace rather than the project, enabling unauthorized access to files from SECRET or unpublished projects if the file UUID is known.

Detection Guidance

To detect this vulnerability, check Plane software versions. Run: `plane --version` or inspect the Plane instance's version via the admin dashboard. If the version is 1.3.1 or earlier, the system is vulnerable. Additionally, review logs for unusual file access patterns or unauthorized download attempts from private projects.

Impact Analysis

This vulnerability can lead to confidentiality breaches as attackers can retrieve private files, including issue descriptions or comment attachments, from projects they are not authorized to access. Even low-privileged users like GUESTs can exploit this to download, modify, or delete cross-project assets. Unauthenticated users with a valid workspace anchor can also access private files if they know the file UUID.

Compliance Impact

This vulnerability could violate compliance with GDPR and HIPAA by exposing sensitive project data to unauthorized users. GDPR requires protecting personal data, while HIPAA mandates safeguarding protected health information. Unauthorized access to private files may result in data breaches, leading to legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later immediately. If upgrading is not possible, restrict workspace membership to trusted users only and audit all file assets for unauthorized access. Disable guest access temporarily if feasible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105631. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart