CVE-2026-30242 is a Server-Side Request Forgery (SSRF) vulnerability affecting Plane, an open-source project management tool, in versions prior to 1.2.3. It allows authenticated attackers with workspace ADMIN privileges to craft webhooks pointing to internal network addresses due to incomplete IP validation. This enables the server to make requests to these internal resources and return their responses, leading to full response read-back. Rated 8.5 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N), the vulnerability is easily exploitable over the network with low privileges and complexity, potentially leading to high confidentiality impact. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. However, the vulnerability has garnered some community discussion, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.3CPE matchmatch criteria | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.