Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.
References
| Link | Resource |
|---|---|
| https://github.com/makeplane/plane/releases/tag/v1.3.1 | Product Release Notes |
| https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx | Exploit Mitigation Vendor Advisory |
| https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx | Exploit Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-06-10 16:17
Updated : 2026-06-17 10:53
NVD link : CVE-2026-46558
Mitre link : CVE-2026-46558
CVE.ORG link : CVE-2026-46558
JSON object : View
Products Affected
plane
- plane
