Impact
Plane’s asset‑management API fails to verify that the authenticated user belongs to the targeted workspace. An attacker who is a member of one workspace can supply that workspace’s slug and an asset ID to acquire presigned URLs, delete, or duplicate assets controlled by another workspace. The flaw enables cross‑tenant data exposure, data deletion, and the movement of files into an attacker‑controlled workspace.
Affected Systems
The vulnerability is present in Plane. No specific affected product versions are listed in the vendor’s advisory. Organizations running any unsupported or older version of Plane should review their deployment for potential exposure.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the flaw is not currently listed in the CISA KEV catalog. The likely attack vector is an authenticated user within a workspace who submits a request to the asset‑management API with the victim’s workspace slug and asset ID. Because the API omits a membership check, the request succeeds, exposing sensitive data or causing destructive actions.
OpenCVE Enrichment