CRITICAL 9.8 CVE-2026-105639 Published 5 Oct 2026

Plane Project Management Tool Signup Flaw Lets Attackers Join Workspaces

Worried this affects your website?

Plane, an open-source project management tool, is affected by a signup flow authentication vulnerability prior to version 1.4.0.

The signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check. An unauthenticated attacker who knows a target's email can register an account using that address, then call GET /api/users/me/workspaces/invitations/ to enumerate pending invitations. The WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint.

  • Attacker can accept an invitation as the target and join a workspace at the invited role.
  • The term pre-auth describes the attacker's initial state: no credential before signup; enumeration and join requests use the session created by signup.
  • Fixed in version 1.4.0.

Reference: CVE-2026-105639 on NVD

← Back to Security News