Executive brief
Plane is an open-source project management platform used by teams to track tasks, sprints, and workflows. A security flaw in the platform's file management system allows a user from one organization to access, copy, or delete files belonging to a completely different organization. This could lead to the theft of sensitive project documents or the permanent loss of data if an attacker deletes files from a victim's workspace.
Technical details
Plane versions 1.3.0 and earlier contain an Insecure Direct Object Reference (IDOR) / Broken Object Level Authorization (BOLA) vulnerability in the asset-management API. The affected endpoints accept workspace slugs and asset identifiers as path parameters but fail to verify if the authenticated requester is a member of the targeted workspace. An attacker with valid credentials for any workspace can access presigned URLs for files, delete assets, or duplicate them into their own workspace by supplying a victim's workspace slug and asset ID. As of the advisory date, no patch is available as the vendor could not be reached for coordination.
Affected products
- Plane Plane <= 1.3.0
Timeline
- 2026-05-28: other: Vendor notified by CERT/CC
- 2026-07-21: disclosed: Public disclosure via CERT/CC and NVD