Executive brief
Plane, an open-source project management platform, contained a security flaw that allowed users in one workspace to access or modify data in another. An authenticated user could view, copy, delete, or overwrite files and assets (such as company logos or project attachments) belonging to different organizations or teams on the same server. This could lead to significant data theft, loss of information, or unauthorized changes to a company's project environment.
Technical details
Plane's V2 asset subsystem contained two authorization flaws in `WorkspaceFileAssetEndpoint` and `DuplicateAssetEndpoint`. The application failed to verify workspace membership when processing requests to create, read, patch, or delete assets via workspace-slugged API routes. Additionally, the asset duplication feature only validated the destination workspace, allowing users to copy source assets from any workspace by UUID without permission checks. An attacker with a standard account could exploit this to download private assets, delete victim files, or deface other workspaces by overwriting logos. This issue is patched in version 1.3.1 by enforcing workspace membership checks and scoping asset lookups to workspaces where the caller is an active member.
Affected products
- makeplane Plane < 1.3.1
Timeline
- 2026-03-23: other: Vulnerability validated by researcher
- 2026-05-14: patched: Version 1.3.1 released
- 2026-05-15: advisory: GitHub Security Advisory published
- 2026-06-10: disclosed: CVE published to NVD