HIGH 8.7 NVD
CVE-2026-105632
Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in tha
Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
References
- https://github.com/makeplane/plane/commit/e1ef42023ab66b5e722a8750e1bc5ba0d413a3ee
- https://github.com/makeplane/plane/pull/9333
- https://github.com/makeplane/plane/releases/tag/v1.4.0
- https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm
- https://github.com/makeplane/plane/security/advisories/GHSA-45hc-q4mw-jhxm
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-10-05 via NVD.
vulnfeed aggregates 7729 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.