Description
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/workspaces/{slug}/modules/ through WorkspaceModulesEndpoint return records from every project in a workspace without checking whether the requester belongs to each project. Any authenticated workspace member, including a Guest with access to only one project, can enumerate names, descriptions, sprint dates, issue counts, progress snapshots, external integration IDs, linked URLs, and member lists for cycles and modules in private projects. The sibling WorkspaceLabelsEndpoint and WorkspaceStatesEndpoint apply the correct project__project_projectmember__member=request.user filter, making the cycle and module endpoints inconsistent outliers. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 4.3 Medium
EPSS: n/a
KEV: No
Impact: Information Disclosure of private project metadata to all workspace members
Action: Apply Patch
AI Analysis

Impact

The Plane application allows any authenticated workspace member to query the /api/workspaces/{slug}/cycles/ and /api/workspaces/{slug}/modules/ endpoints. Because these endpoints omit the project-membership check, a user—including a Guest who normally has access to only one project—can retrieve detailed metadata from private projects, such as names, descriptions, timestamps, issue counts, progress snapshots, integration identifiers, URLs, and member lists. This makes confidential data of those private projects visible to all workspace members and constitutes a moderate severity information‑disclosure flaw (CWE‑200 and CWE‑863).

Affected Systems

makeplane:plane versions earlier than 1.4.0 are affected. All releases before the 1.4.0 tag in the repository contain the vulnerable endpoints and lack the necessary project-membership filter for workspace cycles and module queries.

Risk and Exploitability

The CVSS v3.1 score of 4.3 suggests moderate risk; the vulnerability requires authentication and is limited to users already in the workspace, so the exploitation likelihood is moderate. EPSS is not reported, indicating limited known exploitation activity, and the flaw is not listed in the CISA KEV catalog. Any authenticated user can exploit the flaw by issuing simple GET requests over the network, and the inconsistent filtering across endpoints provides a straightforward attack path for full disclosure of private project metadata.

Generated by OpenCVE AI on October 5, 2026 at 18:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Plane application to version 1.4.0 or later, which implements the missing project-membership filter for cycle and module endpoints.
  • If an immediate upgrade is not feasible, temporarily limit workspace membership so that only authorized roles can query cycle and module data, or restrict Guest access to workspaces containing private projects.
  • Audit all API endpoints to confirm that project membership checks are enforced consistently, and consider adding additional hardening or logging for suspicious access patterns.

Generated by OpenCVE AI on October 5, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/cycles/ through WorkspaceCyclesEndpoint and GET /api/workspaces/{slug}/modules/ through WorkspaceModulesEndpoint return records from every project in a workspace without checking whether the requester belongs to each project. Any authenticated workspace member, including a Guest with access to only one project, can enumerate names, descriptions, sprint dates, issue counts, progress snapshots, external integration IDs, linked URLs, and member lists for cycles and modules in private projects. The sibling WorkspaceLabelsEndpoint and WorkspaceStatesEndpoint apply the correct project__project_projectmember__member=request.user filter, making the cycle and module endpoints inconsistent outliers. This issue is fixed in 1.4.0.
Title Plane: Workspace cycle and module endpoints missing project-membership filter expose private project metadata to any workspace member
Weaknesses CWE-200
CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T16:51:25.444Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104963

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:11.770

Modified: 2026-10-05T17:17:11.910

Link: CVE-2026-104963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:15:10Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-863

    Incorrect Authorization