CVE-2026-46558 is a high-severity vulnerability in Plane, an open-source project management tool. Prior to version 1.3.1, a cross-workspace asset authorization bypass allows any authenticated user to read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.
CVE-2026-40102 affects Plane versions 1.3.0 and below and is fixed in 1.3.1. The issue is an ORM Field Reference Injection in SavedAnalyticEndpoint: a user-controlled segment query parameter was passed directly into a Django F() expression without the allowlist validation used by the regular AnalyticsEndpoint. An authenticated workspace MEMBER could craft a request to the saved analytics endpoint and caus [truncated]
CVE-2026-39374 is a vulnerability in the Plane open-source project management tool. Prior to version 1.3.0, a project member with ADMIN or MEMBER role could modify issue start_date and target_date across the entire Plane instance, regardless of workspace or project membership. The IssueBulkUpdateDateEndpoint did not filter issues by workspace or project, enabling cross-boundary data modification. This iss [truncated]
CVE-2025-69284 is a medium-severity vulnerability in Plane, an open-source project management tool. Prior to version 1.2.0, a guest user could access the `/api/workspaces/:slug/members/` endpoint, listing users on a specific workspace they joined, including identifying admin users' email addresses via the `display_name` field. This issue was fixed in version 1.2.0.