Impact
An SSRF flaw exists in the work‑item link unfurling function of Plane, allowing an authenticated project member to instruct the server to fetch arbitrary internal targets. The engineer can read the response body, including sensitive data such as cloud metadata at 169.254.169.254, and display it as a link title or favicon. The flaw is a classic server‑side request forgery (CWE‑918) and can expose confidential internal information, potentially facilitating further attacks.
Affected Systems
The vulnerability affects the Plane open‑source project management tool from makeplane. Versions prior to 1.4.0, in particular the 1.3.1 GA release, retain the incomplete fix. The complete hardening exists in the Plane main branch following pull request 9163, but it has not been merged into earlier tags. Users deploying any release before 1.4.0 are at risk.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. No EPSS score is available, and the issue is not listed in the CISA KEV catalog, suggesting that it is not widely exploited yet. However, the attack requires an authenticated project member, meaning that any user with project access can trigger the SSRF. Once triggered, the attacker can read internal HTTP responses, with the potential for further pivoting or privilege escalation if the internal environment exposes additional services.
OpenCVE Enrichment