Sceawere
Vulnerability Detail
CVE-2026-104973UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane SSRF via DNS Rebinding
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 3h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-918: Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-30242 validates webhook IP addresses only when the webhook is created in apps/api/plane/app/serializers/webhook.py. The delivery task in apps/api/plane/bgtasks/webhook_task.py performs a separate DNS resolution when sending the request and does not validate the resolved IP address, allowing DNS rebinding to bypass the SSRF protection. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-10-05T18:17:32.290Z",
"pubdate": "2026-10-05T18:17:32.290Z",
"executiveSummary": "Plane, an open-source project management tool, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability due to incomplete validation logic. The flaw exists because webhook IP address validation is only enforced during the initial resource creation phase within the API layer, rather than at the point of request execution.\nThe vulnerability arises from a discrepancy between the validation logic in the serializer and the actual execution logic in the background task processor. By leveraging DNS rebinding, an attacker can bypass the initial check, allowing the system to send requests to internal network resources or unauthorized services. This impact includes the potential for unauthorized data exfiltration, interaction with internal services (such as metadata services in cloud environments), and the circumvention of network access control lists. The vulnerability affects versions of Plane prior to 1.4.0. Successful exploitation requires an attacker to possess the ability to control or influence the DNS resolution path for a user-supplied webhook URL.",
"technicalDetails": "The root cause of this SSRF vulnerability is the inconsistent enforcement of security constraints across different stages of the application lifecycle. Specifically, the implementation in 'apps/api/plane/app/serializers/webhook.py' performs an initial validation of the webhook destination's IP address to prevent requests to restricted or internal network ranges. However, this check is only performed when the webhook object is first defined or updated through the API.\nThe execution of the webhook occurs asynchronously within 'apps/api/plane/bgtasks/webhook_task.py'. When this task is triggered, the underlying HTTP client performs a fresh DNS resolution of the provided hostname. Because the validation performed at the API level is not re-validated against the newly resolved IP address at the time of execution, the application is susceptible to a Time-of-Check to Time-of-Use (TOCTOU) race condition, specifically in the form of DNS rebinding.\nAn attacker can exploit this by providing a domain name that initially resolves to a benign, non-restricted IP address during the validation phase in the API layer. Once the webhook is successfully created, the attacker modifies the DNS records for that domain to point to an internal resource (e.g., 127.0.0.1, a local subnet IP, or an internal cloud metadata endpoint like 169.254.169.254).\nWhen the 'webhook_task.py' background worker attempts to process the delivery, the DNS resolution returns the malicious internal IP address. Since the background task fails to repeat the IP range validation check, the HTTP request is dispatched to the attacker-specified internal destination. The server-side request is then executed with the authority and network context of the Plane application, bypassing host-based or network-level firewall controls. Post-exploitation, this allows an attacker to interact with internal services that are not typically exposed to the public internet, potentially leading to unauthorized data retrieval, interaction with local administrative interfaces, or the leakage of sensitive environment variables or cloud provider credentials.\nThis vulnerability persists across all Plane versions prior to 1.4.0, as the separation between the validation logic in the serializer and the resolution logic in the background task creates an architectural flaw that ignores the dynamic nature of DNS resolution."
}