PT-2026-31015 · Plane · Plane

Mbiesiad

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-27949

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plane versions prior to 1.3.0
Description A security issue exists in Plane's authentication process. The email address of a user is included as a query parameter in the URL during error handling, such as when an invalid magic code is submitted. This practice of transmitting personally identifiable information (PII) via GET request query strings is considered an insecure design. The vulnerable code is located in the authentication utility module (packages/utils/src/auth.ts).
Recommendations Update to version 1.3.0 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27949

Affected Products

Plane