CVE Explorer
CVE-2026-27706
Plane is an an open-source project management tool. Prior to version 1.2.2, a Full Read Server-Side Request Forgery (SSRF) vulnerability has been identified in the "Add Link" feature. This flaw allows an authenticated attacker with general user privileges to send arbitrary GET requests to the internal network and exfiltrate the full response body. By exploiting this vulnerability, an attacker can steal sensitive data from internal services and cloud metadata endpoints. Version 1.2.2 fixes the is
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"plane","vendor":"makeplane","versions":[{"status":"affected","version":"< 1.2.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b1769bf58f7949ebaeef80bb292fd7002ba26590ff8e2e8c57880dacbaf20715 · sha256:0f0c2f892bec5131… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.7,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b1769bf58f7949ebaeef80bb292fd7002ba26590ff8e2e8c57880dacbaf20715 · sha256:0f0c2f892bec5131… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-918","description":"CWE-918: Server-Side Request Forgery (SSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b1769bf58f7949ebaeef80bb292fd7002ba26590ff8e2e8c57880dacbaf20715 · sha256:0f0c2f892bec5131… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/makeplane/plane/releases/tag/v1.2.2","tags":["x_refsource_MISC"],"url":"https://github.com/makeplane/plane/releases/tag/v1.2.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b1769bf58f7949ebaeef80bb292fd7002ba26590ff8e2e8c57880dacbaf20715 · sha256:0f0c2f892bec5131… · /containers/cna/references/1
{"name":"https://github.com/makeplane/plane/security/advisories/GHSA-jcc6-f9v6-f7jw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/makeplane/plane/security/advisories/GHSA-jcc6-f9v6-f7jw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b1769bf58f7949ebaeef80bb292fd7002ba26590ff8e2e8c57880dacbaf20715 · sha256:0f0c2f892bec5131… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.