Impact
The vulnerability is an Insecure Direct Object Reference in Plane’s cycle‑issues endpoint. An authenticated user can submit an issue UUID without the system verifying that the issue belongs to the caller’s workspace, enabling the user to add an issue from any workspace to a cycle they manage. If the target issue is already part of another cycle, the operation removes it from that cycle. This results in a destructive cross‑tenant modification, undermining Integrity for the victim workspace and potentially disrupting project planning.
Affected Systems
The flaw affects all releases of Plane before version 1.4.0. Users running makeplane:plane on older versions should verify their installation version, as the issue has been fixed in the 1.4.0 release.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the exploit probability is unknown due to missing EPSS data. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector requires the attacker to be an authenticated user who has access to the target workspace’s cycle and the ability to submit requests to the API. Since no mitigations are available outside of upgrading, the risk is primarily exploitable by internal actors with sufficient privileges.
OpenCVE Enrichment