CVE-2026-105631: Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can access the affected files?

A workspace member who knows an asset UUID can download assets from private projects in that workspace, even without membership in the asset's project. Unauthenticated callers can retrieve certain issue-description or comment-description assets if they know both a valid public anchor and the asset UUID.

2

What information is required to exploit the issue?

For the workspace asset endpoints, the attacker needs membership in the relevant workspace and a known asset UUID. For the public-anchor endpoint, no authentication is required, but the caller must know a valid anchor and the target asset UUID.

3

Which deployments are affected?

Plane versions prior to 1.4.0 are affected. The issue involves file assets associated with private or unpublished projects within a workspace.

4

How can the issue be remediated?

Upgrade Plane to version 1.4.0, which fixes the affected asset lookup behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203