PT-2026-31015 · Plane · Plane
Mbiesiad
·
Published
2026-04-07
·
Updated
2026-04-08
·
CVE-2026-27949
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Plane versions prior to 1.3.0
Description
A security issue exists in Plane's authentication process. The email address of a user is included as a query parameter in the URL during error handling, such as when an invalid magic code is submitted. This practice of transmitting personally identifiable information (PII) via GET request query strings is considered an insecure design. The vulnerable code is located in the authentication utility module (packages/utils/src/auth.ts).
Recommendations
Update to version 1.3.0 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Plane