CVE-2026-105639: Plane: Pre-auth workspace invitation hijack via email-squat and self-served invitation token leak in Plane

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, Plane's signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check, while User.email is unique=True. The authenticated user can call GET /api/users/me/workspaces/invitations/, which returns each WorkspaceMemberInvite whose email matches request.user.email. WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint. An unauthenticated attacker who knows a target's email can register an account using that address, enumerate pending invitations, and accept an invitation as the target, joining a workspace at the invited role. The term pre-auth describes the attacker's initial state: the attacker has no credential before signup, while the enumeration and join requests use the session created by that signup. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Plane deployments running versions prior to 1.4.0 are affected. The vulnerable signup behavior applies where an attacker can register an account using another person's email address.

2

What does an attacker need to exploit this issue?

The attacker needs to know the email address of a person with a pending workspace invitation. They can then sign up using that address, use the resulting authenticated session to retrieve matching invitations and their tokens, and accept an invitation at its assigned role.

3

Is attacker authentication required?

No existing credential is required before the attack. The attacker creates their own logged-in session through the signup flow; that session is then used to enumerate and accept the target's invitation.

4

What is the impact if exploitation succeeds?

An attacker can join a workspace as the invited user at the role assigned in that pending invitation. The issue exposes invitation tokens through the invitation enumeration endpoint, allowing the protected join endpoint to be used.

5

How can teams determine whether they may be affected?

Verify the deployed Plane version; versions before 1.4.0 are affected. Review whether pending workspace invitations exist for email addresses that could be registered without an out-of-band ownership check.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203