Impact
The Plane application allows any authenticated workspace member to query the /api/workspaces/{slug}/cycles/ and /api/workspaces/{slug}/modules/ endpoints. Because these endpoints omit the project-membership check, a user—including a Guest who normally has access to only one project—can retrieve detailed metadata from private projects, such as names, descriptions, timestamps, issue counts, progress snapshots, integration identifiers, URLs, and member lists. This makes confidential data of those private projects visible to all workspace members and constitutes a moderate severity information‑disclosure flaw (CWE‑200 and CWE‑863).
Affected Systems
makeplane:plane versions earlier than 1.4.0 are affected. All releases before the 1.4.0 tag in the repository contain the vulnerable endpoints and lack the necessary project-membership filter for workspace cycles and module queries.
Risk and Exploitability
The CVSS v3.1 score of 4.3 suggests moderate risk; the vulnerability requires authentication and is limited to users already in the workspace, so the exploitation likelihood is moderate. EPSS is not reported, indicating limited known exploitation activity, and the flaw is not listed in the CISA KEV catalog. Any authenticated user can exploit the flaw by issuing simple GET requests over the network, and the inconsistent filtering across endpoints provides a straightforward attack path for full disclosure of private project metadata.
OpenCVE Enrichment