Impact
Plane, an open‑source project management platform, has an authentication‑protected stored cross‑site scripting flaw in its intake feature. The flaw exists because the view that creates intake issues writes the supplied HTML directly to the database without sanitization. An attacker can embed malicious JavaScript that, when executed by a project participant or viewer of a closed intake item, runs in their browser session and steals a long‑lived API token. The exfiltrated token grants the attacker full API access to the victim’s account, effectively allowing account takeover and unauthorized actions inside the application.
Affected Systems
The affected product is Plane by makeplane, versions prior to 1.4.0 (including v1.3.1). An upgrade to Plane 1.4.0 removes the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Exploitation requires only an authenticated user to create an intake issue, so any user— even a newly registered account with no workspace memberships—is sufficient to seed the attack vector. The lack of an EPSS score and absence from the KEV catalog do not diminish the inherent risk, as the flaw is active, reachable over the web, and directly leads to token theft. The attack is likely to be carried out via the application’s web interface by an authenticated attacker who subsequently waits for a target to open the malicious link.
OpenCVE Enrichment