CVE-2026-104956: Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by` on public deploy boards (DoS + blind oracle)
Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts groupby and subgroupby query parameters and passes them without an allowlist to grouped paginators, where they are used as ORM field names by F(field), .values(field), .orderby(field), and Window partitionby operations. An anonymous attacker can supply arbitrary field paths that trigger an unhandled FieldError or KeyError and an HTTP 500 response, or force the ORM to resolve -separated relational paths as a blind traversal oracle. This is the same field-name injection class addressed by earlier orderby sanitization, but that remediation left groupby and subgroupby unvalidated. The issue does not directly disclose column values because issuegroupvalues() returns an empty list for unknown fields, the result projection uses a fixed requiredfields list, and the subgrouped path raises KeyError before serialization. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated exploitation?
Plane deployments running versions before 1.4.0 that expose public deploy boards are affected. The vulnerable public issues endpoint can be reached without authentication.
What does an attacker need to exploit this issue?
An attacker only needs network access to the public issues endpoint and can supply crafted group_by or sub_group_by query parameters. No privileges or user interaction are required.
What impact can be observed from exploitation?
Crafted field paths can cause unhandled FieldError or KeyError exceptions and HTTP 500 responses, creating a denial-of-service condition. Relational paths separated by double underscores may also be used as a blind traversal oracle, but the issue does not directly disclose column values.
What should be done if upgrading is not immediately possible?
Restrict unauthenticated access to public deploy boards or the affected public issues endpoint until upgrading to 1.4.0. This removes the anonymous attack path described for the vulnerable parameters.
How can defenders identify attempted exploitation?
Look for requests to the unauthenticated public issues endpoint containing unusual or arbitrary group_by or sub_group_by values, especially values with double-underscore-separated relational paths. Associated application errors may include FieldError or KeyError and HTTP 500 responses.