CVE-2026-105636
Deferred Deferred - Pending Action

Open Redirect to Internal Resource Access in Plane

Vulnerability report for CVE-2026-105636, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: GitHub, Inc.

Description

Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
makeplane plane < 1.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105636 is a Server-Side Request Forgery (SSRF) vulnerability in the Plane project management tool affecting versions up to 1.3.1. The issue occurs in the webhook delivery system where the application follows HTTP redirects without re-validating the final destination. An attacker can register a webhook pointing to a controlled public endpoint that redirects to internal addresses. The Plane worker then fetches internal resources, including cloud metadata, and stores responses in webhook logs where the attacker can retrieve them.

Detection Guidance

To detect this vulnerability, check Plane versions prior to 1.4.0. Inspect webhook logs for unusual internal network requests or redirects. Monitor outbound connections from Plane workers to internal IP ranges or cloud metadata endpoints. Review network traffic for requests to 169.254.169.254 (AWS IMDS), 169.254.169.253 (Azure IMDS), or similar internal addresses.

Impact Analysis

This vulnerability allows attackers to access internal network resources from the worker's network. It can expose cloud provider credentials (like AWS IMDS or Azure IMDS), internal services (API, database, message queues), and sensitive data stored in webhook logs. Attackers could use this to compromise cloud accounts or gain access to internal systems.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection. It may result in data breaches exposing personal or health information, potentially violating GDPR's data protection principles or HIPAA's security rules regarding unauthorized access to protected health information.

Mitigation Strategies

Upgrade Plane to version 1.4.0 or later. If upgrading is not immediately possible, disable webhook functionality or restrict webhook URLs to trusted domains. Ensure ENABLE_SIGNUP is set to 0 to prevent unauthorized workspace creation. Review and remove any sensitive data from webhook logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105636. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart