CVE-2026-104978: Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance
Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which invitations are vulnerable to takeover?
Pending invitations sent to email addresses that have not yet registered with Plane are vulnerable. An attacker can register an account using the invited address without mailbox verification and then accept the invitation.
What does an attacker need to exploit this issue?
The attacker needs an authenticated Plane account, the target workspace slug and project ID, and a pending invitation for an unregistered email address. Exploitation also relies on the invitation list endpoint being accessible to authenticated users and the join endpoint accepting an email address alone.
What access does successful exploitation provide?
The attacker-controlled account is added to the target workspace and project. The vulnerability has high confidentiality and integrity impact and affects a different security scope.
What version fixes the issue?
Upgrade Plane to version 1.4.0 or later. Versions prior to 1.4.0 are affected.