CVE-2025-48070: Plane has insecure permissions in UserSerializer
Plane is open-source project management software. Versions prior to 0.23 have insecure permissions in UserSerializer that allows users to change fields that are meant to be read-only, such as email. This can lead to account takeover when chained with another vulnerability such as cross-site scripting (XSS). Version 0.23 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48070?
CVE-2025-48070 has a high severity level due to the potential for account takeover.
How do I fix CVE-2025-48070?
To fix CVE-2025-48070, upgrade to Plane version 0.23 or later.
What causes the vulnerability in CVE-2025-48070?
The vulnerability in CVE-2025-48070 is caused by insecure permissions in UserSerializer that allow modification of read-only fields.
Who is affected by CVE-2025-48070?
Users of Plane versions prior to 0.23 are affected by CVE-2025-48070.
What can happen if CVE-2025-48070 is exploited?
Exploitation of CVE-2025-48070 can lead to unauthorized account access and potential account takeover.