Sceawere
Vulnerability Detail
CVE-2026-105639UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Plane Insecure Invitation Token Exposure
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 2h ago
- Vendor
- makeplane
- Product
- plane
- Attack Type
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-10-05T19:17:18.213Z",
"pubdate": "2026-10-05T19:17:18.213Z",
"executiveSummary": "Plane, an open-source project management tool, contains a critical vulnerability in its signup flow prior to version 1.4.0, leading to unauthorized workspace access.\nThe vulnerability is categorized as an insecure direct object reference and authentication bypass, enabling an attacker to hijack workspace invitations intended for other users.\nBy registering an account with a known target's email address, an attacker can leverage the application's session management to enumerate workspace invitations tied to that email.\nBecause the system fails to perform out-of-band ownership verification during the signup process, the attacker is granted access to the account of the target's email address.\nThis flaw exposes sensitive invitation tokens through the API, allowing the attacker to join workspaces at the role level originally assigned to the target user.\nThe risk is high, as it facilitates unauthorized access to private project data and workspace infrastructure without requiring prior credentials, utilizing only the target's email address.",
"technicalDetails": "The vulnerability resides in the interaction between the account signup flow and the invitation management API in Plane versions prior to 1.4.0.\nThe root cause is twofold: the absence of an out-of-band email ownership verification process during the account registration phase, and the insecure serialization of the WorkspaceMemberInvite model.\nWhen a user signs up, the application creates a User record with the provided email address without confirming that the registrant actually controls the email account.\nOnce the signup is successful, the application establishes a session for the attacker. The attacker can then issue a request to GET /api/users/me/workspaces/invitations/.\nThe backend performs a lookup for WorkspaceMemberInvite objects matching the authenticated session's email address.\nThe WorkspaceMemberInviteSerializer incorrectly utilizes fields = '__all__', which includes the private token required to finalize the workspace join request.\nAttack flow: 1. The attacker identifies a target email address. 2. The attacker performs a signup using the target email. 3. The system creates a logged-in session for the attacker under the target's email identity. 4. The attacker calls the invitation endpoint, which retrieves all pending invitations for that email due to the established session identity. 5. The API response returns the secret invitation tokens. 6. The attacker uses the token to join the workspace as the target user.\nThis allows the attacker to gain unauthorized access to the target's authorized workspaces. The exposure of internal tokens via the API response indicates a failure to properly limit serialized fields to only public-facing or safe attributes.\nAuthentication is technically achieved by the attacker via the signup process, bypassing the intended email ownership check. The impact is significant, as it grants full access to workspace resources assigned to the target email."
}