Impact
GET /api/workspaces/{slug}/entity-search/?query_type=user_mention returns workspace‑member display names, UUIDs, and avatar URLs to any authenticated user who knows the workspace slug, even when the caller is not a member. The endpoint is protected only by a generic authentication check and performs no workspace‑membership validation. This failure of authorization (CWE‑862) allows an attacker to enumerate members of any workspace and view project‐member details, providing sensitive internal user information that could be leveraged for social engineering or credential‑replay attacks.
Affected Systems
Plane, the open‑source project‑management tool from makeplane, is affected in all releases prior to 1.4.0. Any deployment using version 1.3.x or older is potentially vulnerable, as the entity‑search endpoint lacks proper workspace‑membership checks.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. EPSS data is not available, and the flaw is not listed in CISA KEV, suggesting no publicly known exploits yet. The attack vector is inferred to be remote API calls; an authenticated user needs only to know a workspace slug, which may be discovered through other enumeration techniques. Once authenticated, the attacker can send requests to the exposed endpoint and obtain member identifiers, compromising confidentiality and possibly facilitating further attacks. The vulnerability can be exploited by any authenticated user with knowledge of the slug, making it a broad threat to all users of older Plane installations.
OpenCVE Enrichment