CRITICAL
9.1 CVE-2026-105638 Published 5 Oct 2026
Plane Project Management Tool OTP Brute-Force Vulnerability
Worried this affects your website?
Plane, an open-source project management tool, is affected by a magic-code OTP brute-force vulnerability before version 1.4.0.
Its magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter or lockout mechanism.
- An incorrect code does not increment a counter, invalidate the Redis entry, or lock the email address.
- The verifier extends django.views.View rather than DRF's APIView, so the configured AnonRateThrottle limit does not apply.
- The middleware stack has no Django-level rate limiter such as django-ratelimit, django-axes, or IP-throttling middleware.
This vulnerability is fixed in version 1.4.0.
Reference: CVE-2026-105638 on NVD
← Back to Security News