CVE-2026-105641: Plane: Hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY shipped in aio/cli community deployment manifests — session forgery and live-server auth bypass

Published Oct 5, 2026
·
Updated

Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRETKEY and LIVESERVERSECRETKEY defaults that remain active when operators do not override them. The top-level setup.sh randomizes secrets only for the development Docker Compose path, leaving unchanged aio and cli community deployments with shared production secrets. Knowledge of SECRETKEY enables attackers to forge Django-signed values and compromise accounts or sessions. Knowledge of LIVESERVERSECRETKEY bypasses live-service authentication on unchanged community deployments. This issue is fixed in 1.4.0.

Affected Software

1 affected component
Plane Plane<1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Plane to a version that resolves this vulnerability.

    Fixed in 1.4.0

Event History

Oct 5, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected by the shared secrets?

The affected paths are the aio community and cli community deployment manifests when operators leave SECRET_KEY and LIVE_SERVER_SECRET_KEY at their shipped defaults. The development Docker Compose path is different: its top-level setup.sh randomizes secrets.

2

What does an attacker need to exploit this issue?

An attacker needs knowledge of the publicly known shipped SECRET_KEY or LIVE_SERVER_SECRET_KEY values on an unchanged deployment. The SECRET_KEY can be used to forge Django-signed values and compromise accounts or sessions, while the live-server secret can bypass live-service authentication.

3

How can operators determine whether they are exposed?

Review aio or cli community deployment configuration and determine whether SECRET_KEY and LIVE_SERVER_SECRET_KEY were explicitly overridden. Deployments still using the manifest-provided values are affected.

4

What should be done if an affected deployment cannot be upgraded immediately?

Replace both SECRET_KEY and LIVE_SERVER_SECRET_KEY with unique, securely generated values rather than retaining the shipped defaults. Upgrade to Plane 1.4.0 when possible, as it contains the fix.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203