Sceawere
Vulnerability Detail
CVE-2026-105628UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane SSRF via Avatar Synchronization
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 1d ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-918: Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-10-05T18:17:35.917Z",
"pubdate": "2026-10-05T18:17:35.917Z",
"executiveSummary": "Plane, prior to version 1.4.0, is vulnerable to a Server-Side Request Forgery (SSRF) flaw during the OAuth avatar synchronization process.\nThe vulnerability originates from the application's failure to perform internal IP validation or restrict redirect behaviors when fetching remote avatar resources.\nAn unauthenticated or authenticated attacker can manipulate the avatar_url parameter provided via OAuth providers to force the application server to conduct outbound HTTP requests against arbitrary internal network resources.\nBy leveraging 3xx redirect responses, the attacker can redirect the server's request to sensitive internal metadata endpoints or services not intended for public access.\nThe application captures the resulting response and processes it as an avatar file, storing it in the system.\nThis stored asset can subsequently be accessed via the /api/assets/v2/static/{asset_id}/ endpoint, effectively exfiltrating the contents of the internal resource to the attacker.\nThis flaw poses a significant risk to internal network confidentiality, as it allows attackers to bypass network perimeters to query cloud metadata services or internal APIs.",
"technicalDetails": "The vulnerability resides in the OAuth authentication flow where Plane processes user profile metadata, specifically the 'avatar_url', to synchronize user profile images.\nThe root cause is a lack of input validation and protocol-level restrictions on the HTTP client used to fetch remote assets. The implementation performs a server-side GET request without validating whether the target destination resolves to an internal IP address (e.g., 169.254.169.254, 127.0.0.1, or RFC 1918 addresses).\nFurthermore, the HTTP client follows 3xx HTTP redirects by default, allowing for SSRF bypass techniques. An attacker can supply a URL pointing to a malicious server under their control that issues a redirect to a restricted internal resource.\nThe attack flow proceeds as follows: 1) The attacker initiates an OAuth login flow or modifies existing OAuth provider data to include a crafted 'avatar_url'. 2) The Plane server parses this URL and initiates an HTTP GET request to the provided address. 3) The malicious server responds with a 302 or 301 redirect pointing to an internal target (e.g., 'http://169.254.169.254/latest/meta-data/iam/security-credentials/'). 4) The Plane backend follows the redirect, interacts with the internal endpoint, and retrieves the sensitive response content. 5) The application stores the response body as a binary file representing the user's avatar. 6) The attacker accesses the exfiltrated content by querying the publicly accessible path '/api/assets/v2/static/{asset_id}/' associated with the malicious user's avatar.\nThis vulnerability is particularly dangerous in cloud-hosted environments (e.g., AWS, GCP, Azure), where internal metadata services can be queried to obtain IAM roles, security tokens, or environment-specific configuration data without requiring authentication.\nThe impact includes the potential for unauthorized data exfiltration, reconnaissance of the internal network topology, and privilege escalation if the retrieved metadata contains valid cloud credentials.\nThe issue affects all versions of Plane prior to 1.4.0, at which point internal network protection and redirect handling logic were implemented to remediate the vulnerability."
}