CVE-2025-69284: In plane.io, a Guest User to a Workspace can still be able to see list of members
Plane is an an open-source project management tool. In plane.io, a guest user doesn't have a permission to access https[:]//app[.]plane[.]so/[:]slug/settings. Prior to Plane version 1.2.0, a problem occurs when the /api/workspaces/:slug/members/ is accessible by guest and able to list of users on a specific workspace that they joined. Since the displayname in the response is actually the handler of the email, a malicious guest can still identify admin users' email addresses. Version 1.2.0 fixes this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69284?
CVE-2025-69284 has been classified as a moderate severity vulnerability.
How do I fix CVE-2025-69284?
To mitigate CVE-2025-69284, upgrade to Plane version 1.2.0 or later.
Who is affected by CVE-2025-69284?
Users of Plane versions prior to 1.2.0 are affected by CVE-2025-69284.
What does CVE-2025-69284 exploit?
CVE-2025-69284 exploits unauthorized access to the members' API endpoint by guest users.
Is there a workaround for CVE-2025-69284?
There are no effective workarounds for CVE-2025-69284; upgrading is recommended.