Impact
Plane, a project management platform, allows authenticated users to change the allowed_rate_limit field of their API tokens through the PATCH /api/users/api-tokens/{token_id}/ endpoint. The server does not validate the new limit value, permitting users to set it to an arbitrarily high number. As a result, malicious actors can bypass the intended API rate‑limiting controls, generate high‑volume automated requests, and potentially exhaust backend resources.
Affected Systems
The vulnerability impacts installations of the Makeplane Plane project before version 1.4.0. Any deployed instance that has not applied the 1.4.0 release is subject to this weakness.
Risk and Exploitability
The CVSS base score of 5.4 indicates a medium severity vulnerability. The exploitability is high because the attacker only needs valid authentication, which is typically granted to legitimate users. External exploit probability data is unavailable, but the lack of server‑side validation suggests that the flaw is straightforward to exploit for any authenticated user. Because the flaw does not involve privileged escalation or remote code execution, it is not listed in the CISA KEV catalog. Attack vectors therefore rely on normal API usage by legitimate accounts.
OpenCVE Enrichment