Sceawere

Vulnerability Detail

CVE-2026-104977UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SSRF in Plane Link Unfurling

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-918: Server-Side Request Forgery (SSRF)
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, the fix for CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, an SSRF in work-item link unfurling shipped in v1.2.2, remains incomplete in the v1.3.1 GA release. Any authenticated project member can make the server fetch attacker-selected internal targets, including cloud metadata at 169.254.169.254, and read the response body returned as the link title or favicon. Complete hardening exists on main in PR 9163 but was not included in an earlier released tag. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-10-05T18:17:33.080Z",
  "pubdate": "2026-10-05T18:17:33.080Z",
  "executiveSummary": "Plane, an open-source project management tool, contains an incomplete patch for a Server-Side Request Forgery (SSRF) vulnerability identified in its work-item link unfurling feature. This flaw, tracked as CVE-2026-27706 and GHSA-jcc6-f9v6-f7jw, persists in version 1.3.1 despite initial mitigation efforts in version 1.2.2.\nThe vulnerability allows an authenticated project member to force the application server to initiate unauthorized HTTP requests to arbitrary targets, including restricted internal network resources and cloud metadata services. By weaponizing the link unfurling mechanism, an attacker can extract sensitive data from the internal infrastructure, such as cloud identity tokens, internal service responses, or network metadata.\nThe risk is critical for deployments hosted in cloud environments (e.g., AWS, GCP, Azure) where the metadata service at 169.254.169.254 is reachable. The vulnerability requires valid authentication as a project member, significantly lowering the barrier for exploitation by malicious insiders or compromised user accounts. This issue is officially resolved in version 1.4.0.",
  "technicalDetails": "The vulnerability originates from the lack of robust input validation and egress filtering in the work-item link unfurling component of Plane. The application processes user-provided URLs to fetch metadata, such as the page title or favicon, to improve the user interface for shared links. Because the server does not sufficiently sanitize the destination address or enforce strict network boundaries, an attacker can supply internal, non-routable, or sensitive loopback IP addresses.\nThe attack flow begins when an authenticated user provides a malicious URL within a work item. Upon submission, the server-side component responsible for unfurling the link initiates an outbound request using the server's backend identity. Because the internal network or cloud metadata service (specifically 169.254.169.254) is accessible from the application server, the server forwards the request to the attacker-selected target.\nThe application subsequently processes the response body from the requested target. If the target returns data, the server extracts content such as the HTML <title> tag or the favicon source and reflects this information back in the frontend of the Plane application. This reflects the response body—or portions of it—to the attacker, effectively turning the unfurling feature into a data-exfiltration oracle.\nIn cloud environments, this allows an attacker to query the Instance Metadata Service (IMDS). By crafting a request to the metadata endpoint, the attacker can retrieve sensitive configuration data, including IAM role credentials, instance identity documents, and temporary security tokens. This post-exploitation impact facilitates privilege escalation beyond the application scope, potentially granting the attacker full control over the cloud instance or access to other cloud services linked to the instance's identity.\nWhile initial mitigations were applied in v1.2.2, the hardening was insufficient, leaving the SSRF vector exposed in v1.3.1. Full remediation required more comprehensive URL blacklisting, logic refactoring, and strict ingress/egress filtering at the network or application level, which were ultimately implemented in PR 9163 and finalized in the 1.4.0 release."
}
CVE-2026-104977: SSRF in Plane Link Unfurling (HIGH Severity, CVSS: 7.7) | Sceawere