Impact
The vulnerability allows a Server‑Side Request Forgery in Plane’s OAuth avatar synchronization flow, where the platform fetches an avatar URL supplied by the OAuth provider without validating that the URL points to an external host. Apache Core permits follows redirects by default, so an attacker can craft a URL that redirects to an internal resource, such as a metadata endpoint. The server then stores the response as a user avatar, and the asset is publicly reachable through "/api/assets/v2/static/{asset_id}/", providing a mechanism to exfiltrate data that should remain internal. The primary impact is internal data exfiltration and potential disclosure of sensitive information.
Affected Systems
All releases of makeplane:plane earlier than version 1.4.0 are affected. The flaw exists in the OAuth avatar synchronization feature, which is enabled by default in these versions, and it can be triggered by any user account whose OAuth provider supplies a malicious avatar_url.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity vulnerability. The EPSS value is not available, and the issue is not in the CISA KEV catalog. Based on the description, the attacker must influence the avatar_url returned during the OAuth authentication process; this can be achieved by controlling the OAuth provider or compromising a user account that authorizes the application. Once the server follows the redirect to an internal resource, the data is captured and stored, making the exploit straightforward for an attacker with network access to the server. The risk is elevated for installations with unrestricted outbound connectivity to internal networks.
OpenCVE Enrichment