CVE-2026-104979: Plane: Cross-tenant stored XSS in intake enables account takeover
Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes descriptionhtml through Issue.objects.create(...) without calling validatehtmlcontent from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Who can exploit this issue, and which projects are exposed?
Any authenticated Plane user can exploit it, including a newly created user with no workspace memberships. The target project must have a published DeployBoard with intake enabled.
What user interaction is required for impact?
A project member or a viewer of a closed intake item must click the attacker-planted link. The click can execute JavaScript in that viewer's session and exfiltrate a long-lived API token.
Which versions are affected and what version fixes the issue?
Plane versions prior to 1.4.0 are affected. The issue is fixed in Plane 1.4.0.