PT-2026-21942 · Plane · Plane

Teppay

·

Published

2026-02-25

·

Updated

2026-02-28

·

CVE-2026-27706

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.2.2
Description A Server-Side Request Forgery (SSRF) flaw exists in the "Add Link" feature of Plane, allowing an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and retrieve the full response body. This can lead to the theft of sensitive data from internal services and cloud metadata endpoints.
Recommendations Update to version 1.2.2 or later.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-27706
GHSA-JCC6-F9V6-F7JW

Affected Products

Plane