Summary
CVE-2026-105639 is a critical authentication and authorization bypass vulnerability in Plane, the open-source project management platform maintained by makeplane. An unauthenticated attacker who knows a target’s email address can hijack a pending workspace invitation intended for that victim, gaining unauthorized membership in the workspace at the invited role level — up to full Admin control. The flaw carries a CVSS v3.1 base score of 9.8 (Critical) and affects all versions up to and including 1.3.1.
Technical details
- Root cause: The vulnerability is a chain of three distinct weaknesses in Plane’s authentication and invitation flow:
- The
SignUpAuthEndpointcreates aUserdatabase row and establishes a fully authenticated session for any submitted email address with no out-of-band proof of email ownership, allowing "email squatting." UserWorkspaceInvitationsViewSetserializes workspace invitation objects usingfields = "__all__", which inadvertently exposes the secrettokenfield (and aninvite_linkcontaining that token as a query parameter) used to authorize joining a workspace.WorkspaceJoinEndpointvalidates only a string-equality match of the submitted token and resolves the joining account purely by email, without verifying that the account’s email ownership has been confirmed.
- The
- Trigger conditions: The attacker only needs to know (or guess) the email address of a user with a pending workspace invitation; no credentials or prior access are required.
- Attack vector: Network-based, pre-authentication (PR:N, UI:N). The exploit requires three unauthenticated HTTP requests: (1) sign up using the victim’s email to "squat" it and obtain a session, (2) call
GET /api/users/me/workspaces/invitations/to enumerate pending invitations and leaked tokens, (3) submit the leaked token to the join endpoint to accept the invitation as the attacker-controlled account. - Impact: Full confidentiality, integrity, and availability compromise of the affected workspace. Depending on the invited role, an attacker can read member rosters and project/issue data, modify workspace settings and content, add other members, or — if the hijacked invitation was Admin-level — delete projects or the entire workspace. Legitimate invitees are also permanently locked out of signing up, since the victim’s email is now bound to the attacker’s account under the database’s unique email constraint.
Affected software
- Plane (makeplane/plane) versions ≤ 1.3.1
- Fixed in version 1.4.0
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Upgrade Plane to version 1.4.0 or later, which removes the
tokenfield from the invitation serializer’s output, requires verified proof of email ownership before signup completes, and enforcesis_email_verified=Truebefore a user can accept a workspace invitation. - If immediate patching is not possible:
- Restrict or monitor access to
/api/users/me/workspaces/invitations/and the workspace join endpoint at the network/WAF layer until the upgrade can be applied. - Audit existing user accounts for unverified emails (
is_email_verified=False) that joined a workspace shortly after account creation, and for duplicate/squatted signups matching known invitees. - Review workspace membership lists for unexpected members added via invitation acceptance, particularly at Admin or other privileged roles, and revoke access for any accounts that cannot be confirmed as legitimate.
- Restrict or monitor access to

