Impact
The Plane web application allows an authenticated user who shares a workspace with a secret project to download files that belong to that project, bypassing the intended project‑level access control. This results in the unauthorized disclosure of files such as issue attachments, comment descriptions, page descriptions, and project covers that should be protected. The weakness is an authorization bypass (CWE‑639) and privilege escalation (CWE‑862).
Affected Systems
Plane versions before 1.4.0 are affected. The vulnerability is present in the makeplane:plane product, affecting all workspaces where project‑bound FileAsset objects such as ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER can be accessed through the GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint.
Risk and Exploitability
With a CVSS score of 6.5, this vulnerability is of moderate severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated from within a workspace; an attacker must be a member of the workspace but not a member of the secret project and must know the target asset UUID. Once the bypass is used, an attacker obtains direct access to the signed download URL and can retrieve the secret file contents.
OpenCVE Enrichment