CVE-2026-15342 is a multi-tenant authorization flaw in Plane's asset-management API. Authenticated users from one workspace can access, delete, or duplicate assets from another workspace by providing the victim workspace slug and asset ID. Affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying the requester's workspace membership. This flaw allows cro [truncated]
CVE-2026-10850 is a vulnerability in Plane CE 1.3.1 that allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint. This vulnerability has a CVSS score of 6.9, indicating a medium severity. The vulnerability exists due to insufficient input validation and sanitization in the description_html field, [truncated]