Sceawere

Vulnerability Detail

CVE-2026-105635UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Plane Project Invitation Information Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
2h ago
Vendor
makeplane
Product
plane
Attack Type
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-10-05T19:17:17.503Z",
  "pubdate": "2026-10-05T19:17:17.503Z",
  "executiveSummary": "Plane prior to version 1.4.0 is susceptible to an Information Disclosure vulnerability within the ProjectJoinEndpoint, stemming from insecure access control policies.\nThe vulnerability allows unauthenticated remote attackers to retrieve sensitive invitation data, including email addresses, authentication tokens, and member roles, by querying specific API endpoints.\nThe root cause is the assignment of permission_classes = [AllowAny] to the GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ endpoint, which bypasses all authentication and authorization checks.\nFurthermore, the corresponding POST method for joining projects fails to validate invitation tokens, relying solely on email matching. This permits an attacker who has discovered a target invitation UUID to register an account using the exposed email address and subsequently hijack the invitation.\nThe exploitability of this flaw is high, as it requires no prior authentication and minimal information beyond the target project's invitation UUID. This could lead to unauthorized access to restricted project spaces and potential account takeover scenarios for intended invitees.\nImpact includes the compromise of confidential project metadata and unauthorized access to private workspaces, necessitating an immediate upgrade to version 1.4.0.",
  "technicalDetails": "The vulnerability resides in the ProjectJoinEndpoint component of the Plane application, specifically within the API architecture handling project invitations.\nThe primary mechanism of failure is a misconfiguration of the Django Rest Framework permission classes. By explicitly defining permission_classes = [AllowAny] for the GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ endpoint, the application exposes the full ProjectMemberInvite database record to any unauthenticated actor.\nThe leaked data structures include sensitive fields such as the recipient's email address, the secret invitation token, and the assigned membership role. This represents a significant security oversight, as this data is intended only for the authorized invitee.\nThe attack flow follows a structured exploitation path: First, an attacker probes the API endpoint with known or brute-forced invitation UUIDs. Because of the AllowAny permission class, the server returns the complete object, including the associated email address.\nSecond, the attacker leverages the secondary vulnerability in the POST /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ endpoint. While this endpoint is intended to process the invitation acceptance, it performs inadequate validation. Specifically, the implementation only verifies that the submitted email address matches the email field stored in the previously retrieved ProjectMemberInvite record, entirely neglecting to validate the cryptographically secure invitation token.\nBy registering an account with the disclosed email address, an attacker can satisfy the server's weak validation logic and join the target project as a member, effectively impersonating the original invitee. This bypasses the intended security boundary of the invitation system.\nThe combination of indiscriminate information disclosure and flawed input validation enables an attacker to gain unauthorized access to project data, sensitive member lists, and internal workflows. As this was fixed in 1.4.0, the vulnerability confirms that the lack of request-level authorization and the failure to implement token-based integrity checks were the primary drivers of this security failure.\nThis vulnerability is fully exploitable over the network and requires no special privileges, rendering the application insecure in any environment where the API is reachable by untrusted actors."
}
CVE-2026-105635: Plane Project Invitation Information Disclosure (HIGH Severity, CVSS: 7.4) | Sceawere