Impact
A REST‑style API in Plane allows bulk deletion of issue links and re‑parenting of sub‑issues using issue identifiers supplied in the request body or URL. The code fails to validate that the supplied identifiers belong to the caller’s workspace or project. Consequently, an authenticated member or administrator can delete association records linked to foreign issues or move those issues under another target, thereby exfiltrating metadata or corrupting cross‑workspace relationships. The flaw satisfies CWE-639, a failure in political segregation of user data.
Affected Systems
Plane, an open‑source project management tool, up to but not including version 1.4.0 is affected. The vulnerability resides in the BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/. All releases through 1.3.x may be compromised; the issue is resolved in release 1.4.0.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate impact and the vulnerability is exploitable only by users who have legitimate workspace membership. An attacker must discover or guess foreign issue identifiers, but the lack of scope checks makes the attack straightforward once such IDs are known. The EPSS score is currently not available, and the flaw is not listed in CISA KEV, suggesting no large‑scale exploitation yet. Nevertheless, an internal collaborator could use the API to manipulate or expose data across workspaces, warranting immediate remediation.
OpenCVE Enrichment