CRITICAL
9.8 CVE-2026-105639 Published 5 Oct 2026
Plane Project Management Tool Signup Flaw Lets Attackers Join Workspaces
Worried this affects your website?
Plane, an open-source project management tool, is affected by a signup flow authentication vulnerability prior to version 1.4.0.
The signup flow creates a logged-in User row for any submitted email without an out-of-band ownership check. An unauthenticated attacker who knows a target's email can register an account using that address, then call GET /api/users/me/workspaces/invitations/ to enumerate pending invitations. The WorkSpaceMemberInviteSerializer uses fields = "all", exposing the token that protects the invitation join endpoint.
- Attacker can accept an invitation as the target and join a workspace at the invited role.
- The term pre-auth describes the attacker's initial state: no credential before signup; enumeration and join requests use the session created by signup.
- Fixed in version 1.4.0.
Reference: CVE-2026-105639 on NVD
← Back to Security News