Executive brief
Plane, an open-source project management platform, contains a security flaw that allows any authorized project member to modify task dates in other projects or workspaces. By exploiting this vulnerability, a user could change the start and target dates of any task across the entire organization, even if they do not have permission to view or edit that specific project. This could lead to significant disruption of project timelines, deadlines, and operational planning.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the IssueBulkUpdateDateEndpoint of Plane prior to version 1.3.0. The endpoint, located in apps/api/plane/app/views/issue/base.py, uses Issue.objects.filter(id__in=issue_ids) to fetch issues for bulk updates without verifying that the issues belong to the requester's workspace or project. An attacker with ADMIN or MEMBER privileges in any project can submit a POST request to their own project's bulk update endpoint containing the UUIDs of issues from other projects. This allows the attacker to modify the start_date and target_date of any issue in the instance. The vulnerability is addressed in version 1.3.0 by implementing proper workspace and project filtering.
Affected products
- Makeplane Plane < 1.3.0
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory
- 2026-04-07: patched: Fixed in version 1.3.0