Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owning project. An authenticated user who belongs to the same workspace, is not a member of the victim's secret project, and knows the target asset UUID can receive a 302 redirect to a signed download URL. The intended project-scoped route for the same asset correctly returns 403. Confirmed affected project-bound asset types are ISSUE_ATTACHMENT, COMMENT_DESCRIPTION, PAGE_DESCRIPTION, and PROJECT_COVER. This bypass exposes private file content protected by the secret project boundary. This issue is fixed in 1.4.0. | |
| Title | Plane: Authorization bypass in workspace-scoped asset download endpoint exposes secret project file assets to non-project workspace users | |
| Weaknesses | CWE-639 CWE-862 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T17:51:34.599Z
Reserved: 2026-10-02T18:16:13.629Z
Link: CVE-2026-104960
No data.
Status : Deferred
Published: 2026-10-05T17:17:11.307
Modified: 2026-10-05T17:17:11.427
Link: CVE-2026-104960
No data.
OpenCVE Enrichment
No data.
