Description
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Unauthorized Information Disclosure
Action: Patch Now
AI Analysis

Impact

GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace‑member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a member. The endpoint is protected only by a generic authentication check and performs no workspace‑membership validation. This failure of authorization (CWE‑862) allows an attacker to enumerate members of any workspace and view project‐member details, providing sensitive internal user information that could be leveraged for social engineering or credential‑replay attacks.

Affected Systems

Plane, the open‑source project‑management tool from makeplane, is affected in all releases prior to 1.4.0. Any deployment using version 1.3.x or older is potentially vulnerable, as the entity‑search endpoint lacks proper workspace‑membership checks.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS data is not available, and the flaw is not listed in CISA KEV, suggesting no publicly known exploits yet. The attack vector is inferred to be remote API calls; an authenticated user needs only to know a workspace slug, which may be discovered through other enumeration techniques. Once authenticated, the attacker can send requests to the exposed endpoint and obtain member identifiers, compromising confidentiality and possibly facilitating further attacks. The vulnerability can be exploited by any authenticated user with knowledge of the slug, making it a broad threat to all users of older Plane installations.

Generated by OpenCVE AI on October 5, 2026 at 18:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Plane version 1.4.0 or later to apply the enforced workspace‑membership check for the entity‑search API.
  • Verify that all API endpoints incorporate role‑based membership validation and expose data only to authorized workspace members.
  • Audit API logs for anomalous use of /api/workspaces/*/entity-search/ and apply rate limiting or alerts to detect potential abuse.

Generated by OpenCVE AI on October 5, 2026 at 18:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane

Mon, 05 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace-member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a workspace member. The endpoint also exposes ProjectMember rows under the same condition. SearchEndpoint in apps/api/plane/app/views/search/base.py inherits BaseAPIView with only permission_classes = [IsAuthenticated] and performs no workspace-membership check. This issue is fixed in 1.4.0.
Title Plane: Cross-workspace member enumeration via /api/workspaces/{slug}/entity-search/
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:05:38.700Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104968

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-05T17:17:12.627

Modified: 2026-10-05T17:17:12.743

Link: CVE-2026-104968

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T18:45:19Z

Weaknesses