Description
Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same workspace, is not a member of the victim's secret project, and knows the target asset UUID can receive a 302 redirect to a signed download URL. The intended project-scoped route for the same asset correctly returns 403. Confirmed affected project-bound asset types are ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER. This bypass exposes private file content protected by the secret project boundary. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of secret project assets
Action: Patch
AI Analysis

Impact

The Plane web application allows an authenticated user who shares a workspace with a secret project to download files that belong to that project, bypassing the intended project‑level access control. This results in the unauthorized disclosure of files such as issue attachments, comment descriptions, page descriptions, and project covers that should be protected. The weakness is an authorization bypass (CWE‑639) and privilege escalation (CWE‑862).

Affected Systems

Plane versions before 1.4.0 are affected. The vulnerability is present in the makeplane:plane product, affecting all workspaces where project‑bound FileAsset objects such as ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER can be accessed through the GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint.

Risk and Exploitability

With a CVSS score of 6.5, this vulnerability is of moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated from within a workspace; an attacker must be a member of the workspace but not a member of the secret project and must know the target asset UUID. Once the bypass is used, an attacker obtains direct access to the signed download URL and can retrieve the secret file contents.

Generated by OpenCVE AI on October 5, 2026 at 18:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Plane version 1.4.0 or newer to patch the authorization bypass in the workspace‑scoped asset download endpoint.
  • If an upgrade cannot be performed immediately, restrict or block GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ for users who are not members of the owning project to prevent exploitation.
  • Review and enforce strict access controls on workspace and secret project boundaries to ensure that project‑bound assets are only accessible to authorized project members.

Generated by OpenCVE AI on October 5, 2026 at 18:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same workspace, is not a member of the victim's secret project, and knows the target asset UUID can receive a 302 redirect to a signed download URL. The intended project-scoped route for the same asset correctly returns 403. Confirmed affected project-bound asset types are ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER. This bypass exposes private file content protected by the secret project boundary. This issue is fixed in 1.4.0.
Title Plane: Authorization bypass in workspace-scoped asset download endpoint exposes secret project file assets to non-project workspace users
Weaknesses CWE-639
CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T17:51:34.599Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104960

cve-icon Vulnrichment

Updated: 2026-10-05T17:51:17.367Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:11.307

Modified: 2026-10-05T18:17:31.780

Link: CVE-2026-104960

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:30:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key

  • CWE-862

    Missing Authorization