← Retour aux CVEs
CVE-2026-27706
HIGH7.7
Description
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints. Version 1.2.2 fixes the issue.
Details CVE
Score CVSS v3.17.7
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurNONE
Publie2/25/2026
Derniere modification2/27/2026
Sourcenvd
Observations honeypot0
Produits affectes
plane:plane
Faiblesses (CWE)
CWE-918
References
https://github.com/makeplane/plane/releases/tag/v1.2.2(security-advisories@github.com)
https://github.com/makeplane/plane/security/advisories/GHSA-jcc6-f9v6-f7jw(security-advisories@github.com)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.