Impact
Plane is an open‑source project‑management platform. A Project Member with role ID 15 can send a PATCH request to /api/workspaces/{workspace_slug}/projects/{project_id}/members/{member_pk}/ to change another user's role. The existing logic only blocks assigning a role higher than the requester's role; assigning an equal role bypasses validation, allowing a Project Guest (role 5) to be promoted to Member without Project Admin approval. This unauthorized promotion grants the guest the expanded capabilities of a Member and lets a regular member bypass project governance.
Affected Systems
All deployments of makeplane:plane running any release older than v1.4.0 are affected. The vulnerability was introduced prior to version 1.4.0 and is fixed in that release. Users should verify their current version and upgrade accordingly.
Risk and Exploitability
CVSS score of 5.4 indicates a moderate‑severity flaw. The vulnerability is exploitable via an authenticated PATCH request to the project‑member update endpoint. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. An attacker who can act as a Project Member can promote another guest to a Member, thus gaining additional project privileges without administrative oversight.
OpenCVE Enrichment