CVE-2026-105636: CWE-918: Server-Side Request Forgery (SSRF) in makeplane plane
Description
CVE-2026-105636 is a critical Server-Side Request Forgery (SSRF) vulnerability in the open-source project management tool Plane prior to version 1.4.0. The flaw exists in the webhook delivery task, which follows HTTP redirects without validating the final redirect target URL. This allows an attacker who can create a workspace to register a webhook that redirects to internal network addresses, enabling the Plane worker to access internal resources such as cloud metadata. The response is stored in webhook logs accessible to the attacker. This vulnerability is fixed in Plane version 1.4.0.
CVSS v3.1
Score 9.9critical
Affected software
makeplane
plane
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Plane versions prior to 1.4.0 contain an SSRF vulnerability (CWE-918) in the webhook delivery task located in apps/api/plane/bgtasks/webhook_task.py. The code calls requests.post() without setting allow_redirects=False and does not validate the final URL after redirects. Although validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, it does not check the final redirect target. An attacker with workspace creation privileges can register a webhook pointing to an attacker-controlled endpoint that issues a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, which the attacker can retrieve via the workspace webhook-logs API. The vulnerability is resolved in version 1.4.0.
Potential Impact
An attacker with the ability to create a workspace can exploit this SSRF vulnerability to make the Plane worker fetch internal network resources, including sensitive cloud metadata. The fetched data is logged and accessible to the attacker, potentially leading to disclosure of sensitive internal information. The vulnerability has a CVSS 3.1 score of 9.9 (critical), indicating high impact on confidentiality, integrity, and availability.
Mitigation Recommendations
This vulnerability is fixed in Plane version 1.4.0. Users should upgrade to version 1.4.0 or later to remediate this issue. No additional mitigations are specified in the advisory. Patch status is confirmed by the vendor advisory stating the fix is in 1.4.0.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-05T16:40:39.611Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac3ed962cdf04f6562b6561
Added to database: 10/05/2026, 18:33:58 UTC
Last enriched: 10/05/2026, 18:48:52 UTC
Last updated: 10/05/2026, 18:56:34 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.