Skip to main content

CVE-2026-105636: CWE-918: Server-Side Request Forgery (SSRF) in makeplane plane

0
Critical
VulnerabilityCVE-2026-105636cvecve-2026-105636cwe-918
Published: 10/05/2026 (10/05/2026, 18:02:53 UTC)
Source: CVE Database V5
Vendor/Project: makeplane
Product: plane

Description

CVE-2026-105636 is a critical Server-Side Request Forgery (SSRF) vulnerability in the open-source project management tool Plane prior to version 1.4.0. The flaw exists in the webhook delivery task, which follows HTTP redirects without validating the final redirect target URL. This allows an attacker who can create a workspace to register a webhook that redirects to internal network addresses, enabling the Plane worker to access internal resources such as cloud metadata. The response is stored in webhook logs accessible to the attacker. This vulnerability is fixed in Plane version 1.4.0.

CVSS v3.1

Score 9.9critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected software

makeplane

plane

Affected versions
<1.4.0
GitHub Actionsmore threats →ai
makeplane/plane
pkg:github/makeplane/plane
Affected versions
<1.4.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/05/2026, 18:48:52 UTC

Technical Analysis

Plane versions prior to 1.4.0 contain an SSRF vulnerability (CWE-918) in the webhook delivery task located in apps/api/plane/bgtasks/webhook_task.py. The code calls requests.post() without setting allow_redirects=False and does not validate the final URL after redirects. Although validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, it does not check the final redirect target. An attacker with workspace creation privileges can register a webhook pointing to an attacker-controlled endpoint that issues a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, which the attacker can retrieve via the workspace webhook-logs API. The vulnerability is resolved in version 1.4.0.

Potential Impact

An attacker with the ability to create a workspace can exploit this SSRF vulnerability to make the Plane worker fetch internal network resources, including sensitive cloud metadata. The fetched data is logged and accessible to the attacker, potentially leading to disclosure of sensitive internal information. The vulnerability has a CVSS 3.1 score of 9.9 (critical), indicating high impact on confidentiality, integrity, and availability.

Mitigation Recommendations

This vulnerability is fixed in Plane version 1.4.0. Users should upgrade to version 1.4.0 or later to remediate this issue. No additional mitigations are specified in the advisory. Patch status is confirmed by the vendor advisory stating the fix is in 1.4.0.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-05T16:40:39.611Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac3ed962cdf04f6562b6561

Added to database: 10/05/2026, 18:33:58 UTC

Last enriched: 10/05/2026, 18:48:52 UTC

Last updated: 10/05/2026, 18:56:34 UTC

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses