Junglewise Threat Intelligence

CVE-2026-10850: Plane Plane CE stored XSS in intake work item description

CVE-2026-10850 · Severity: info · CVSS 6.9 · Published 2026-06-17

Executive brief

Plane CE, an open-source project management platform, contains a security vulnerability that allows low-privileged users to inject malicious scripts into project work items. An attacker with basic access to a project can use this to execute code in the browsers of other users, such as administrators, when they view the affected task. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Plane CE 1.3.1. The flaw is located in the 'description_html' field of the API v1 intake endpoint used for creating work items. A remote attacker with low-privileged project member credentials can submit a request containing malicious JavaScript or HTML. When other users, including those with higher privileges, view the created intake item, the payload executes in their browser context. This can result in session hijacking or unauthorized data access. The vulnerability is tracked as CWE-79.

Affected products

  • Plane Plane CE 1.3.1

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References