CVE tracker
393 subscribers
5.79K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-104978 - Plane: Invitation Hijack in Project Join Flow via Missing Authorization and Email-Only Acceptance

CVE ID :CVE-2026-104978
Published : Oct. 5, 2026, 5:48 p.m. | 25 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, Plane's project invitation list endpoint is accessible to any authenticated user who knows the workspace slug and project ID, while the public project invitation join endpoint accepts an invitation based only on a submitted email address. When a pending invitation targets an email address that has not registered with Plane, an attacker can enumerate the invitation, register an account using the invited email without mailbox verification, and accept the invitation. The attacker-controlled account is then added to the target workspace and project. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104979 - Plane: Cross-tenant stored XSS in intake enables account takeover

CVE ID :CVE-2026-104979
Published : Oct. 5, 2026, 5:49 p.m. | 24 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, IntakeIssuePublicViewSet.create in Plane v1.3.1 writes description_html through Issue.objects.create(...) without calling validate_html_content from nh3. Any authenticated user, including a new user with no workspace memberships, can plant arbitrary HTML in a project that has a published DeployBoard with intake enabled. When a project member or viewer of a closed intake item clicks the planted link, the TipTap \tjavascript: parser bypass and the target="_self" click handler execute JavaScript in the viewer's session and exfiltrate a long-lived API token. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93320 - BuildKit improperly handles special files in build snapshots

CVE ID :CVE-2026-93320
Published : Oct. 5, 2026, 5:50 p.m. | 23 minutes ago
Description :BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105628 - Plane: OAuth Avatar Redirect SSRF Leads to Internal Data Exfiltration via Static Asset Endpoint

CVE ID :CVE-2026-105628
Published : Oct. 5, 2026, 5:51 p.m. | 23 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, Plane's OAuth avatar synchronization flow fetches avatar_url from provider user data through a server-side HTTP request without internal IP validation and follows redirects by default. An attacker can provide an avatar URL that redirects to an internal-only resource, such as a metadata endpoint, and Plane uploads the fetched response as a user avatar file. The object is then exposed through /api/assets/v2/static/{asset_id}/, allowing exfiltration of internally fetched content. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105629 - Plane: Cross-Tenant Destructive IDOR: Estimate Point Deletion via Unscoped Primary Key Lookup

CVE ID :CVE-2026-105629
Published : Oct. 5, 2026, 5:53 p.m. | 21 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, BulkEstimatePointEndpoint.destroy resolves an estimate point through a bare primary-key lookup without workspace, project, or estimate scoping. An administrator or member of one workspace can permanently delete an estimate point belonging to another workspace by supplying the target UUID in a URL under the attacker's own workspace. This creates a destructive cross-tenant IDOR. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93322 - Malformed MergeOp can crash the BuildKit daemon

CVE ID :CVE-2026-93322
Published : Oct. 5, 2026, 5:53 p.m. | 20 minutes ago
Description :A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Severity: 6.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105630 - Plane: Stored XSS via SVG attachment served inline on the application origin (account takeover)

CVE ID :CVE-2026-105630
Published : Oct. 5, 2026, 5:54 p.m. | 20 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, an authenticated low-privilege workspace member, including a Guest, can upload an image/svg+xml file as a generic or issue attachment. The file retains the attacker-controlled Content-Type, and the asset-download endpoint creates a presigned URL with Content-Disposition: inline. In the default self-hosted MinIO deployment, the asset URL is served from the same origin as the Plane application, allowing embedded SVG JavaScript to execute in the application's security context. A victim, including a workspace administrator, who opens the link can have the session compromised through stored XSS, leading to account takeover. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105631 - Plane: asset download endpoints scope file lookups to the workspace (not the project / published entity) → cross-project & unauthenticated private-file disclosure

CVE ID :CVE-2026-105631
Published : Oct. 5, 2026, 5:55 p.m. | 18 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, WorkspaceFileAssetEndpoint.get and WorkspaceAssetDownloadEndpoint.get resolve FileAsset records within a workspace without checking membership in the asset's project, allowing a workspace member to download assets from private projects when the asset UUID is known. EntityAssetEndpoint.get is a separate public-anchor endpoint that grants AllowAny access and scopes the lookup only to the anchor's workspace rather than its published entity or project. An unauthenticated caller who knows a valid anchor and an asset UUID can therefore retrieve issue-description or comment-description assets belonging to unpublished or private projects in that workspace. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93323 - Oversized Dockerfile or .dockerignore can exhaust buildkitd memory

CVE ID :CVE-2026-93323
Published : Oct. 5, 2026, 5:57 p.m. | 17 minutes ago
Description :The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.
Severity: 6.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105632 - Plane: Broken Access Control - joinProject GraphQL mutation allows self-join into private (secret) projects

CVE ID :CVE-2026-105632
Published : Oct. 5, 2026, 5:57 p.m. | 16 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, the GraphQL joinProject mutation lets any workspace member add themselves to any project in that workspace including network=0 (secret/private) projects they were never invited to and grants them a full Member role (read + write). The resolver checks only workspace-level membership/role and never checks the target project's visibility (network). This collapses project-level tenant isolation within a workspace: a low-privilege member can read and modify confidential data in every private project. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105633 - Plane: Issue Attachment Ownership Hijacking via Missing `issue_id` Scope

CVE ID :CVE-2026-105633
Published : Oct. 5, 2026, 5:58 p.m. | 15 minutes ago
Description :Plane is an open-source project management tool. Prior to 1.4.0, the V2 issue-attachment PATCH endpoint accepts issue_id in the URL but omits it from the database query. A project member can use an issue_id they control in the URL while targeting another user's attachment by its pk UUID. Because the server matches only pk, workspace, and project_id, it modifies the attachment regardless of the issue_id in the URL. When the attachment is pending and has not been confirmed as uploaded, the PATCH handler sets created_by = request.user and transfers attachment ownership to the attacker. This issue is fixed in 1.4.0.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105686 - Penpot: Repeated chunk index causes temporary-storage amplification

CVE ID :CVE-2026-105686
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the chunked media upload RPC validates that a chunk index is in range but neither rejects an already stored index nor replaces its previous object. An authenticated user can repeatedly upload the same valid index, causing each successful request to allocate another temporary object and increasing stored bytes beyond the upload session's declared logical size. Assembly detects the inconsistent chunk count only after allocation. This issue is fixed in version 2.18.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105687 - Penpot: A team admin (non-owner) can remove the team owner via ::delete-team-member — missing owner-protection

CVE ID :CVE-2026-105687
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-team-member RPC allows a team administrator to remove any member other than themselves but does not protect the team owner. A non-owner administrator can delete the owner's team-profile-rel membership and lock the owner out of the team and its projects, files, fonts, and media. This issue is fixed in version 2.18.0.
Severity: 4.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105688 - Penpot: Team admin can escalate to owner via team invitation (missing owner-role guard on the invitation path)

CVE ID :CVE-2026-105688
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, create-team-invitations and the invitation acceptance path allow a non-owner team administrator to assign the owner role because invitation roles are persisted and applied without the role-ceiling check used by update-team-member-role. An administrator can invite another account as an owner, create multiple owners, and then use the new owner account to obtain owner-only control over the team. This issue is fixed in version 2.18.0.
Severity: 6.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105689 - Penpot: SSRF guard bypass via IPv6 transition addresses (NAT64/6to4/Teredo) in webhook delivery and media download

CVE ID :CVE-2026-105689
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, app.util.ssrf/blocked-address? relies on Java InetAddress predicates that do not classify NAT64, 6to4, or Teredo addresses and applies additional CIDR checks only to IPv4 values. Exploitation requires routing through a NAT64 gateway or an attacker-controlled DNS AAAA record; cloud environments with NAT64 gateways are directly exploitable. A user controlling a media import URL, or an administrator controlling a webhook URL, can then supply an IPv6 transition address that embeds a cloud-metadata, loopback, link-local, or private IPv4 target and bypasses the intended SSRF restrictions. Media import can disclose response bodies, while webhook delivery can expose response status as a network-probing side channel. This issue is fixed in version 2.18.0.
Severity: 6.0 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105690 - Penpot: Server-side session not invalidated on logout; stale auth-token cookie remains valid for full profile access

CVE ID :CVE-2026-105690
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, logout clears the browser's auth-token cookie without revoking the corresponding server-side session. A previously captured session token remains usable after the victim logs out and can continue to make authenticated requests with the victim's authority until natural expiration. This issue is fixed in version 2.18.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105691 - Penpot: Authenticated OS Command Injection in Penpot SVG Exporter via Legacy fill-color

CVE ID :CVE-2026-105691
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the SVG exporter places an attacker-controlled text object's fill-color value into a ppmcolormask command string and executes that string through child_process.exec. A user who can edit a file can store shell metacharacters in the fill color and trigger SVG export, causing commands to execute with the exporter service's privileges. The same export can be triggered through a valid public share link to a malicious file. This vulnerability is fixed in 2.18.0.
Severity: 9.9 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105692 - Penpot: IDOR in Share-Link Deletion Allows Any File Editor to Delete Share-Links They Did Not Create

CVE ID :CVE-2026-105692
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the delete-share-link RPC retrieves a caller-selected share-link ID and verifies only that the caller can edit the parent file. It does not verify that the caller created the share link or has owner or administrator authority, allowing any file editor who knows a share-link UUID to delete links created by other users and revoke external reviewers' access. This issue is fixed in version 2.18.0.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105693 - Penpot: Anonymous share-link token disclosure & page-scope bypass via get-view-only-bundle

CVE ID :CVE-2026-105693
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, the unauthenticated get-view-only-bundle RPC returns every share-link row for a file even when the caller authenticated with only one scoped share link. A holder of a restrictive link can obtain other links' secret IDs, page scopes, comment permissions, and inspection permissions, then replay a more permissive token to access page data that was not included in the original share. This issue is fixed in version 2.18.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105694 - Penpot: Stored XSS via Unsanitised SVG Uploads

CVE ID :CVE-2026-105694
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, authenticated users with file-edit permission can upload SVG media whose scripts, event-handler attributes, and foreignObject elements are stored without sanitization and served as image/svg+xml from the Penpot origin. A victim who navigates to the asset URL executes attacker-controlled JavaScript in that origin, allowing requests and data access with the victim's Penpot session authority. This issue is fixed in version 2.18.0.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-105695 - Penpot: Missing authorization in chunked-upload assembly lets another authenticated user consume a victim's upload session

CVE ID :CVE-2026-105695
Published : Oct. 5, 2026, 8:17 p.m. | 23 minutes ago
Description :Penpot is an open-source design and prototyping platform. Prior to 2.18.0, assemble-chunks retrieves an upload session using only its session ID, while upload-chunk correctly scopes the lookup to the authenticated profile. An authenticated user who obtains another user's live, completed upload-session UUID can assemble the victim's chunks into the attacker's own file, team font, or project import, disclosing the uploaded bytes and deleting the victim's pending session. This issue is fixed in version 2.18.0.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...