PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105631 makeplane CVE debrief

CVE-2026-105631 debrief: Plane asset download endpoints allow cross-project and unauthenticated private-file disclosure. This issue is fixed in version 1.4.0. The vulnerability allows unauthorized access to private project assets, potentially impacting confidentiality. Defenders should verify exposure, apply the fix, and review access controls. The issue arises from WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolving FileAsset records within a workspace without checking membership in the asset's project. An unauthenticated caller who knows a valid anchor and an asset UUID can retrieve issue-description or comment-description assets belonging to projects

Vendor
makeplane
Product
plane
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-07
Advisory published
2026-10-05
Advisory updated
2026-10-07

Who should care

Defenders responsible for open-source project management tools, specifically those using Plane, should assess exposure and apply the fix. This vulnerability allows unauthorized access to private project assets, potentially impacting confidentiality.

Why it matters

CVE-2026-105631 allows unauthorized access to private project assets in Plane, impacting confidentiality. Defenders should verify exposure, apply the fix, and review access controls.

  • Potential unauthorized access to private project assets
  • Possible exposure of sensitive information in issue descriptions or comment descriptions
  • Need to verify workspace and project access controls
  • Priority on upgrading to version 1.4.0 or later

Technical summary

Plane, an open-source project management tool, had a vulnerability in its asset download endpoints. Prior to version 1.4.0, these endpoints resolved FileAsset records within a workspace without checking membership in the asset's project. This allowed a workspace member to download assets from private projects when the asset UUID was known. An unauthenticated caller who knows a valid anchor and an asset UUID could retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace.

Defensive priority

Defenders should prioritize verifying exposure and applying the vendor-provided fix, as this issue allows unauthorized access to private project assets.

Recommended defensive actions

  • Verify if the Plane tool is used in your organization and if versions prior to 1.4.0 are in use.
  • Apply the vendor-provided fix by upgrading to version 1.4.0 or later.
  • Review and update access controls for Plane workspaces and projects to minimize exposure.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record and source item provide details on the vulnerability, including affected versions and fixed versions. However, additional information on exploitation or victim impact is not available. The vulnerability allows unauthorized access to private project assets. Defenders should verify exposure, apply the fix, and review access controls for Plane workspaces and projects to minimize exposure. The fix involves upgrading to version 1.4.0 or later. No additional information on exploitation or victim impact is available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105631 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105631

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105631 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105631

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Plane: asset download endpoints scope file lookups to the workspace (not the project / published

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/105xxx/CVE-2026-105631.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/security/advisories/GHSA-85h2-mhcc-xfmw

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/pull/9288

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/pull/9372

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/commit/4577dc3f7a6b5a198602b602a45c6b0abdc7204b

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/commit/e63f0c3b3404d669ae05dd9050aab72292f87e5c

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/makeplane/plane/releases/tag/v1.4.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.