Description
Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
Published: 2026-10-05
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Account takeover via stored XSS
Action: Immediate Patch
AI Analysis

Impact

Plane, an open‑source project management platform, has an authentication‑protected stored cross‑site scripting flaw in its intake feature. The flaw exists because the view that creates intake issues writes the supplied HTML directly to the database without sanitization. An attacker can embed malicious JavaScript that, when executed by a project participant or viewer of a closed intake item, runs in their browser session and steals a long‑lived API token. The exfiltrated token grants the attacker full API access to the victim’s account, effectively allowing account takeover and unauthorized actions inside the application.

Affected Systems

The affected product is Plane by makeplane, versions prior to 1.4.0 (including v1.3.1). An upgrade to Plane 1.4.0 removes the vulnerability.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. Exploitation requires only an authenticated user to create an intake issue, so any user— even a newly registered account with no workspace memberships—is sufficient to seed the attack vector. The lack of an EPSS score and absence from the KEV catalog do not diminish the inherent risk, as the flaw is active, reachable over the web, and directly leads to token theft. The attack is likely to be carried out via the application’s web interface by an authenticated attacker who subsequently waits for a target to open the malicious link.

Generated by OpenCVE AI on October 5, 2026 at 20:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Plane v1.4.0 or newer to apply the fix that sanitizes intake issue content.
  • If upgrading is not immediately possible, restrict intake creation and issue editing to users who are members of the owner workspace or to administrators only.
  • Disable the intake feature for all projects until the vulnerability is resolved to prevent any stored XSS from being seeded.

Generated by OpenCVE AI on October 5, 2026 at 20:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Makeplane
Makeplane plane
Vendors & Products Makeplane
Makeplane plane
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
Title Plane: Cross-tenant stored XSS in intake enables account takeover
Weaknesses CWE-79
CWE-862
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-05T19:12:00.312Z

Reserved: 2026-10-02T18:16:13.629Z

Link: CVE-2026-104979

cve-icon Vulnrichment

Updated: 2026-10-05T19:11:21.910Z

cve-icon NVD

Status : Deferred

Published: 2026-10-05T18:17:33.420

Modified: 2026-10-05T20:17:10.243

Link: CVE-2026-104979

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T20:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-862

    Missing Authorization