Plane, an open-source project management tool, contains an incomplete remediation of a prior Server-Side Request Forgery vulnerability affecting versions 0.28.0 through 1.2.x. The flaw allows authenticated attackers with low privileges to bypass validation controls by exploiting the favicon fetch functionality, which does not properly validate redirects to private IP addresses when processing HTML link tags. The vulnerability was resolved in version 1.3.0. The vulnerability carries a CVSS score of 7.7 (High) with a network-based attack vector requiring low privileges and no user interaction. The attack has a low complexity rating and could result in high confidentiality impact with cross-site scope, allowing unauthorized access to sensitive information from internal systems. This represents a notable privilege escalation from typical unauthenticated SSRF vulnerabilities. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.00033 indicating minimal real-world exploitation activity to date. No public exploit code has been disclosed, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities catalog. Organizations using affected Plane versions should prioritize upgrading to version 1.3.0 to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.28.0, < 1.3.0CPE matchmatch criteria | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.