Description
Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each endpoint validates only that the caller is a member or administrator of the workspace and project named in the URL. BulkDeleteIssuesEndpoint can destroy CycleIssue and ModuleIssue associations belonging to foreign issues. SubIssuesEndpoint can re-parent foreign issues under an attacker-selected issue and return the foreign issues' metadata. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Cross‑workspace association deletion and unauthorized issue manipulation via unscoped API queries
Action: Apply Patch
AI Analysis

Impact

A REST‑style API in Plane allows bulk deletion of issue links and re‑parenting of sub‑issues using issue identifiers supplied in the request body or URL. The code fails to validate that the supplied identifiers belong to the caller’s workspace or project. Consequently, an authenticated member or administrator can delete association records linked to foreign issues or move those issues under another target, thereby exfiltrating metadata or corrupting cross‑workspace relationships. The flaw satisfies CWE-639, a failure in political segregation of user data.

Affected Systems

Plane, an open‑source project management tool, up to but not including version 1.4.0 is affected. The vulnerability resides in the BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/. All releases through 1.3.x may be compromised; the issue is resolved in release 1.4.0.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact and the vulnerability is exploitable only by users who have legitimate workspace membership. An attacker must discover or guess foreign issue identifiers, but the lack of scope checks makes the attack straightforward once such IDs are known. The EPSS score is currently not available, and the flaw is not listed in CISA KEV, suggesting no large‑scale exploitation yet. Nevertheless, an internal collaborator could use the API to manipulate or expose data across workspaces, warranting immediate remediation.

Generated by OpenCVE AI on October 5, 2026 at 19:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Plane to version 1.4.0 or later, where all affected endpoints validate issue ownership
  • Restrict bulk delete and sub‑issue APIs to users with the minimum necessary privileges and audit calls that reference foreign issue IDs
  • Disable or tightly monitor any API tokens that have cross‑workspace access and enforce least‑privilege principles for workspace administrators

Generated by OpenCVE AI on October 5, 2026 at 19:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, BulkDeleteIssuesEndpoint and SubIssuesEndpoint in apps/api/plane/app/views/issue/ accept body- or URL-supplied issue IDs and operate on them without checking that the IDs belong to the caller's workspace and project. The permission decorator on each endpoint validates only that the caller is a member or administrator of the workspace and project named in the URL. BulkDeleteIssuesEndpoint can destroy CycleIssue and ModuleIssue associations belonging to foreign issues. SubIssuesEndpoint can re-parent foreign issues under an attacker-selected issue and return the foreign issues' metadata. This issue is fixed in 1.4.0.
Title Plane: Cross-workspace association destruction and issue mutation/read via unscoped queries in BulkDeleteIssuesEndpoint and SubIssuesEndpoint
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T18:37:30.774Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104967

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:12.453

Modified: 2026-10-05T19:17:15.430

Link: CVE-2026-104967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T19:15:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key