CVE-2026-104892: Plane: Plaintext logging of API token
Plane is an open-source project management tool. Prior to 1.4.0, aPITokenLogMiddleware logs API keys in plaintext. This allows someone with low privileges to steal user API keys and further escalate their privileges. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who could exploit this issue?
A low-privileged person who can access the plaintext logs containing API keys could steal those keys and use them to escalate privileges.
Which Plane versions are affected?
Plane versions prior to 1.4.0 are affected. The issue is fixed in version 1.4.0.
How can I determine whether API keys may have been exposed?
Review logs produced by affected Plane deployments for API keys written by aPITokenLogMiddleware. Any API key found in accessible plaintext logs should be treated as potentially exposed.