Impact
Plane is an open‑source project management platform. A time‑of‑check to time‑of‑use (TOCTOU) race condition in the InstanceAdminSignUpEndpoint allowed two unauthenticated callers, each specifying a different email address, to observe that no instance administrator existed, create separate User and InstanceAdmin records, and receive sessions with full instance‑admin privileges. Because the account creation logic lacks atomicity or locking, both requests succeed, effectively granting the attacker unlimited administrative control over the Plane instance. The vulnerability results in privilege escalation without needing authentication or any additional privileges, exposing the system to full configuration and data compromise.
Affected Systems
This flaw affects makeplane:plane (Plane). All releases from 0.13 up to just before 1.4.0 are vulnerable, as the InstanceAdminSignUpEndpoint was modified in the 1.4.0 release to add proper concurrency safeguards. Users of earlier versions should consider upgrading immediately; if an upgrade is not possible, the endpoint should be disabled or access restricted. The vendor’s advisory indicates the issue was fixed in the 1.4.0 release, so any version newer than that is not affected.
Risk and Exploitability
With a CVSS base score of 8.1, the vulnerability represents a high‑severity escalation path. The lack of an atomic transaction or row lock makes the race exploitable with simple HTTP requests; an attacker can trigger the conflict by sending two concurrent POST calls to the signup endpoint from two IPs or the same client. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog, but the nature of the flaw (unauthenticated privilege escalation) makes it a serious risk for organizations that expose Plane services. Immediate remediation is advised to prevent an attacker from gaining administrative rights.
OpenCVE Enrichment