Sceawere
Vulnerability Detail
CVE-2026-105637UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Insecure Asset Access Control
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.6
- Creation Date
- 2h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-639: Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, ProjectBulkAssetEndpoint.post in apps/api/plane/app/views/asset/v2.py retrieves assets using id__in=asset_ids and workspace__slug=slug but does not constrain the query with project_id from the URL. A workspace Guest can provide asset UUIDs from another project in the same workspace and reassign their issue_id, comment_id, page_id, draft_issue_id, or project_id to an entity the attacker controls. Plane then treats the attacker's project as the new owner and provides a presigned download URL for the hijacked file. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.6",
"pubDate": "2026-10-05T19:17:17.860Z",
"pubdate": "2026-10-05T19:17:17.860Z",
"executiveSummary": "Plane prior to version 1.4.0 is susceptible to an insecure direct object reference (IDOR) vulnerability within the asset management module.\nThe vulnerability resides in the ProjectBulkAssetEndpoint.post method, which fails to adequately validate asset ownership against the project context defined in the request URL.\nA workspace Guest can exploit this flaw by referencing arbitrary asset UUIDs from any project within the same workspace to reassign ownership attributes such as issue_id, comment_id, or project_id to an attacker-controlled entity.\nThe impact is significant, as it allows unauthorized modification of asset ownership and provides the attacker with presigned download URLs for sensitive files they should not access.\nThis vulnerability requires the attacker to hold at least a Guest-level account within the targeted workspace to perform the unauthorized reassignment operations.\nThe flaw stems from a lack of strict multi-tenant authorization scoping during the bulk asset processing workflow.",
"technicalDetails": "The vulnerability is located in apps/api/plane/app/views/asset/v2.py within the ProjectBulkAssetEndpoint.post function. The core issue is an insufficient access control check when performing bulk operations on assets.\nSpecifically, the application retrieves assets using a query filter defined as id__in=asset_ids and workspace__slug=slug. However, the logic fails to enforce a project-level boundary by omitting a check against the project_id parameter provided in the request URL.\nThis failure creates a logical bypass where the application assumes that any asset existing within the specified workspace is valid for modification, regardless of whether it belongs to the target project.\nAn authenticated Guest user can exploit this by crafting a POST request containing a list of asset UUIDs belonging to a project outside of their current scope. Because the backend query only validates the workspace context, the database returns objects that the attacker should not have authorization to manipulate.\nUpon successful identification of these assets, the endpoint allows the attacker to perform mass updates on sensitive fields, including issue_id, comment_id, page_id, draft_issue_id, or project_id. By modifying these fields, the attacker effectively hijacks the asset, reassigning it to a project or entity under their own control.\nOnce the asset's ownership or association is updated in the database, the application logic proceeds to process the hijacked asset as if it were legitimate. This results in the generation of a presigned download URL, granting the attacker unauthorized access to potentially confidential files or attachments that were previously restricted to specific project members.\nThe attack flow follows these steps: 1) The attacker authenticates as a workspace Guest. 2) The attacker intercepts or crafts a POST request to the affected endpoint. 3) The attacker injects UUIDs of assets belonging to other projects within the same workspace into the payload. 4) The server processes the request, failing to restrict the modification to the project context. 5) The attacker reassigns the asset's associations. 6) The attacker utilizes the resulting presigned URL to retrieve the hijacked file."
}