Sceawere
Vulnerability Detail
CVE-2026-105630UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane Stored XSS via SVG
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.7
- Creation Date
- 3h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application's security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.7",
"pubDate": "2026-10-05T18:17:36.250Z",
"pubdate": "2026-10-05T18:17:36.250Z",
"executiveSummary": "Plane, an open-source project management tool, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability affecting versions prior to 1.4.0.\nThe vulnerability originates from the improper handling of uploaded SVG files, which retain an attacker-controlled 'image/svg+xml' Content-Type and are served with an 'inline' Content-Disposition header.\nIn default self-hosted MinIO configurations, these assets are served from the application's origin, allowing malicious JavaScript embedded within the SVG to execute in the security context of the victim's session.\nThe vulnerability is exploitable by authenticated low-privilege users, including Guests, who can upload malicious files as generic or issue attachments.\nSuccessful exploitation allows an attacker to execute arbitrary scripts in the browser of a victim, such as a workspace administrator, potentially leading to unauthorized actions, data exfiltration, or complete account takeover.\nThe risk is critical due to the potential for privilege escalation and the ability to target high-privileged users within the workspace.",
"technicalDetails": "The root cause of this vulnerability is the failure of the Plane application to sanitize or enforce restrictive Content-Security-Policy (CSP) headers when serving user-uploaded content, specifically SVG files.\nWhen a user uploads a file, the application stores it in the underlying MinIO storage and preserves the user-provided Content-Type. When requested, the asset-download endpoint generates a presigned URL that serves the file with a 'Content-Disposition: inline' header.\nBecause the server serves these files from the same origin as the primary application, browsers interpret the SVG as active content rather than a static binary file. This allows any JavaScript embedded inside the SVG's <script> tags or via 'onload' event handlers to execute within the context of the Plane application's domain.\nThe attack flow proceeds as follows: First, an authenticated attacker with minimal privileges (such as a Guest) uploads a crafted SVG file containing a malicious JavaScript payload to an issue or as a generic attachment. Second, the attacker obtains the presigned URL for the uploaded file. Third, the attacker tricks a target user, such as an administrator, into navigating to this URL. Finally, upon the target user's browser rendering the SVG file, the browser executes the embedded script in the victim's session.\nThis execution enables the attacker to perform actions on behalf of the victim, including accessing sensitive data, changing configuration settings, or exfiltrating session tokens if the application does not strictly enforce 'HttpOnly' flags on all sensitive cookies. Because the application processes these files through the same domain, the malicious script inherits full access to the origin's storage, session state, and API functionality.\nThe vulnerability affects all Plane installations prior to version 1.4.0. It requires valid authentication to perform the initial file upload, but does not require high-level administrative access to trigger the payload, as the attacker can target administrators after the file is successfully hosted on the application's origin."
}