CVE-2026-104962: Plane: Cross-project member roster IDOR in ProjectMemberListCreateAPIEndpoint (missing project scope on reads)
Plane is an open-source project management tool. Prior to 1.4.0, GET /api/v1/workspaces/{slug}/projects/{projectid}/members/ returns the complete project-member roster, including each member's email address, first and last name, display name, avatar, and role. ProjectMemberPermission gates the endpoint, but its SAFEMETHODS branch checks only whether the caller is an active ProjectMember of any project in the workspace and does not bind the check to view.projectid. The view then filters solely by the projectid supplied in the URL. Consequently, any authenticated user who belongs to one project in a workspace, including a Guest, can read the roster of another private project in the same workspace. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can access information from projects they do not belong to?
Any authenticated user who is an active member of at least one project in the same workspace can do so, including users with the Guest role. The affected target can be another private project in that workspace.
What does an attacker need to exploit this issue?
The attacker needs an authenticated Plane account that is an active ProjectMember of any project in the target workspace. They can then request the members endpoint with the ID of another project in that workspace; no user interaction is required.
What information could be disclosed?
The endpoint can disclose the complete member roster of the targeted project, including email addresses, first and last names, display names, avatars, and roles. The issue is limited to information disclosure; no integrity or availability impact is described.
How can we determine whether our instance is affected, and what should we do?
Plane versions prior to 1.4.0 are affected. Upgrade to version 1.4.0; until then, treat any user who belongs to a project in a workspace as potentially able to enumerate member rosters for other projects in that workspace.