HIGH 7.6 NVD
CVE-2026-105628
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a
Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0.
References
- https://github.com/makeplane/plane/commit/04622ce1188c4680951f0001e35efb342fe51615
- https://github.com/makeplane/plane/pull/9163
- https://github.com/makeplane/plane/releases/tag/v1.4.0
- https://github.com/makeplane/plane/security/advisories/GHSA-cv9p-325g-wmv5
- https://github.com/makeplane/plane/security/advisories/GHSA-cv9p-325g-wmv5
This high severity vulnerability with a CVSS score of 7.6 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.