CVE-2026-105635
Deferred Deferred - Pending Action

Information Disclosure in Plane Project Management Tool

Vulnerability report for CVE-2026-105635, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105635 is a vulnerability in the Plane project management tool prior to version 1.4.0. It involves two flaws in the project invitation system. First, an unauthenticated GET endpoint exposes sensitive ProjectMemberInvite details like email, token, and role. Second, the POST endpoint for accepting invitations only checks the email without validating the token, allowing unauthorized users to join projects by knowing the invitation UUID.

Detection Guidance

Check Plane API endpoints for unauthenticated access to /api/workspaces/{slug}/projects/{project_id}/join/{pk}/. Use curl to test GET requests to this endpoint with known workspace slug, project ID, and invite UUID. If it returns sensitive data like email or token without authentication, the system is vulnerable.

Impact Analysis

An attacker could exploit this to disclose project invite emails, register accounts with those emails, and gain unauthorized access to projects without the original token. This could lead to unauthorized project participation, data exposure, or workspace access if project membership grants broader permissions.

Compliance Impact

This vulnerability could violate GDPR and HIPAA by exposing sensitive personal data (emails) and allowing unauthorized access to project data. GDPR requires protecting personal data, and HIPAA mandates strict access controls for health-related information. The exposure of emails and unauthorized access risks non-compliance with these regulations.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later. Ensure the GET endpoint requires authentication and token validation is enforced on POST requests. Verify email ownership before accepting invitations and implement proper access controls.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105635. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart