CVE-2026-105641: Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass
Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRETKEY and LIVESERVERSECRETKEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRETKEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVESERVERSECRETKEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Planeto a version that resolves this vulnerability.Fixed in 1.4.0
Event History
Frequently Asked Questions
Which deployments are affected by the shared secrets?
The affected paths are the aio community and cli community deployment manifests when operators leave SECRET_KEY and LIVE_SERVER_SECRET_KEY at their shipped defaults. The development Docker Compose path is different: its top-level setup.sh randomizes secrets.
What does an attacker need to exploit this issue?
An attacker needs knowledge of the publicly known shipped SECRET_KEY or LIVE_SERVER_SECRET_KEY values on an unchanged deployment. The SECRET_KEY can be used to forge Django-signed values and compromise accounts or sessions, while the live-server secret can bypass live-service authentication.
How can operators determine whether they are exposed?
Review aio or cli community deployment configuration and determine whether SECRET_KEY and LIVE_SERVER_SECRET_KEY were explicitly overridden. Deployments still using the manifest-provided values are affected.
What should be done if an affected deployment cannot be upgraded immediately?
Replace both SECRET_KEY and LIVE_SERVER_SECRET_KEY with unique, securely generated values rather than retaining the shipped defaults. Upgrade to Plane 1.4.0 when possible, as it contains the fix.