Sceawere
Vulnerability Detail
CVE-2026-104979UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Stored XSS via HTML Injection
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.7
- Creation Date
- 3h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.7",
"pubDate": "2026-10-05T18:17:33.420Z",
"pubdate": "2026-10-05T18:17:33.420Z",
"executiveSummary": "Plane versions prior to 1.4.0 are vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability residing within the IntakeIssuePublicViewSet component.\nThe vulnerability occurs because the application fails to sanitize HTML input in the description_html field before persisting it to the database.\nAny authenticated user, regardless of workspace membership status, can exploit this by injecting malicious payloads into intake-enabled projects with a published DeployBoard.\nSuccessful exploitation allows an attacker to execute arbitrary JavaScript within the session context of other project members or viewers.\nThe primary impact is the exfiltration of long-lived API tokens, leading to potential account takeover and unauthorized access to project data.\nThe risk is critical, as it bypasses standard client-side security controls through a combination of improper input validation and a TipTap parser bypass.",
"technicalDetails": "The vulnerability is located in the IntakeIssuePublicViewSet.create method within the Plane application, specifically affecting version 1.3.1 and earlier.\nThe root cause of this security flaw is the direct persistence of user-provided content in the description_html field via the Issue.objects.create() function without invoking necessary security sanitization routines, such as nh3's validate_html_content.\nThe attack vector leverages the public-facing nature of project intake forms. An authenticated user can craft an HTTP request containing malicious HTML and JavaScript, specifically utilizing a TipTap parser bypass technique. By injecting 'javascript:' pseudo-protocol URI schemes and leveraging 'target=_self' attributes within the HTML content, the attacker can force the browser to execute arbitrary script code upon rendering.\nThe attack flow follows a structured sequence: 1) The attacker identifies a target project that has a DeployBoard with intake enabled. 2) The attacker submits an issue through the public intake form, embedding the malicious payload into the description_html field. 3) Because the server-side logic fails to sanitize the input, the payload is stored as-is in the underlying database. 4) A legitimate user, such as a project member or viewer, navigates to the closed intake item or the associated DeployBoard view. 5) When the victim interacts with the planted link, the browser executes the embedded JavaScript within the user's authenticated session context.\nThe post-exploitation behavior primarily targets sensitive session data, specifically the theft of long-lived API tokens. By executing scripts in the victim's session, the attacker can programmatically extract these tokens and transmit them to an external, attacker-controlled server.\nThis vulnerability is particularly severe because it does not require administrative privileges or workspace membership, only basic authentication, effectively lowering the barrier to entry for potential attackers aiming to compromise the integrity and confidentiality of the project management environment."
}