Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.
References
| Link | Resource |
|---|---|
| https://github.com/makeplane/plane/releases/tag/v1.3.1 | Product Release Notes |
| https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx | Exploit Mitigation Vendor Advisory |
| https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx | Exploit Mitigation Vendor Advisory |
Configurations
History
12 Jun 2026, 00:49
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Plane
Plane plane |
|
| References | () https://github.com/makeplane/plane/releases/tag/v1.3.1 - Product, Release Notes | |
| References | () https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx - Exploit, Mitigation, Vendor Advisory | |
| CPE | cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:* |
10 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/makeplane/plane/security/advisories/GHSA-qw87-v5w3-6vxx - |
10 Jun 2026, 16:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-10 16:17
Updated : 2026-06-12 00:49
NVD link : CVE-2026-46558
Mitre link : CVE-2026-46558
CVE.ORG link : CVE-2026-46558
JSON object : View
Products Affected
plane
- plane
