CVE-2026-104956: Plane: Unauthenticated ORM field-name injection via `group_by`/`sub_group_by` on public deploy boards (DoS + blind oracle)

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, the unauthenticated public issues endpoint accepts groupby and subgroupby query parameters and passes them without an allowlist to grouped paginators, where they are used as ORM field names by F(field), .values(field), .orderby(field), and Window partitionby operations. An anonymous attacker can supply arbitrary field paths that trigger an unhandled FieldError or KeyError and an HTTP 500 response, or force the ORM to resolve -separated relational paths as a blind traversal oracle. This is the same field-name injection class addressed by earlier orderby sanitization, but that remediation left groupby and subgroupby unvalidated. The issue does not directly disclose column values because issuegroupvalues() returns an empty list for unknown fields, the result projection uses a fixed requiredfields list, and the subgrouped path raises KeyError before serialization. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated exploitation?

Plane deployments running versions before 1.4.0 that expose public deploy boards are affected. The vulnerable public issues endpoint can be reached without authentication.

2

What does an attacker need to exploit this issue?

An attacker only needs network access to the public issues endpoint and can supply crafted group_by or sub_group_by query parameters. No privileges or user interaction are required.

3

What impact can be observed from exploitation?

Crafted field paths can cause unhandled FieldError or KeyError exceptions and HTTP 500 responses, creating a denial-of-service condition. Relational paths separated by double underscores may also be used as a blind traversal oracle, but the issue does not directly disclose column values.

4

What should be done if upgrading is not immediately possible?

Restrict unauthenticated access to public deploy boards or the affected public issues endpoint until upgrading to 1.4.0. This removes the anonymous attack path described for the vulnerable parameters.

5

How can defenders identify attempted exploitation?

Look for requests to the unauthenticated public issues endpoint containing unusual or arbitrary group_by or sub_group_by values, especially values with double-underscore-separated relational paths. Associated application errors may include FieldError or KeyError and HTTP 500 responses.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203