CVE-2026-104965: Plane: Cross-Tenant Issue Relation Creation via IDOR
Plane is an open-source project management tool. Prior to 1.4.0, the issue-relation endpoint accepts issue UUIDs in the request body without validating that they belong to the caller's workspace. An authenticated user can create relations linking their own issues to issues in any other workspace on the instance, leaking issue metadata through activity events. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must be authenticated to the Plane instance and able to create an issue relation from an issue in their own workspace. They do not need membership in the target workspace.
What information could be exposed?
The attacker can create a cross-workspace relation that leaks issue metadata from the other workspace through activity events. The provided information does not indicate that issue contents or other data can be modified.
Are default deployments affected?
Any Plane deployment prior to 1.4.0 is affected if authenticated users can access the issue-relation endpoint. The issue is fixed in Plane 1.4.0.
How can administrators check for possible exploitation?
Review issue activity events for relations connecting issues across different workspaces, especially relations created by users who are not members of the workspace containing the referenced issue. Such cross-tenant relations are the described exploitation mechanism.