CVE-2026-27949

MEDIUM CVSS 3.1: 4.3 EPSS 0.17%
Updated Jul 24, 2026
Plane
Parameter Value
CVSS 4.3 (MEDIUM)
Affected Versions before 1.3.0
Fixed In 1.3.0
Type CWE-200 (Information Exposure), CWE-598
Vendor Plane
Public PoC No

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice.

The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Plane Plane
cpe:2.3:a:plane:plane:*:*:*:*:*:*:*:*
1.3.0