Impact
The vulnerability allows an attacker to hijack project invitations by exploiting missing authorization checks in the invitation list endpoint and an email-only acceptance mechanism. An attacker who knows a workspace slug and project ID can retrieve pending invitations, then create an account with the same email as the intended invitee without verifying ownership of the mailbox. If the invitation targets an unregistered address, the newly created account can accept the invitation, thereby gaining membership in the target workspace and project. This results in unauthorized user access, potentially compromising the confidentiality and integrity of the workspace, and providing the attacker with whatever permissions are granted to invited members.
Affected Systems
Plane, version 1.4.0 and earlier. Prior to the release of 1.4.0, any authenticated user could query the project invitation list for a known workspace and project, and the public invitation join endpoint accepted the invitation solely based on the supplied email address.
Risk and Exploitability
The product has a CVSS score of 8.2, reflecting high severity. No EPSS score is published, and the vulnerability is not listed in CISA’s KEV catalog, but the flaw is straightforward to exploit once the attacker learns a workspace slug and project ID. Since the authentication requirement is minimal and the email address can be guessed or enumerated, the exploitation likelihood remains high for an attacker with basic social engineering skills.
OpenCVE Enrichment