CyberRota Analysis
AI-GeneratedThe ProjectJoinEndpoint in versions prior to 1.4.0 of the Plane project management tool is vulnerable, allowing unauthenticated users to access sensitive ProjectMemberInvite information, including email addresses and invitation tokens. This flaw enables attackers to exploit the invitation system by registering accounts with invited emails and accepting invitations without proper authorization. Organizations using affected versions should prioritize updating to 1.4.0 to mitigate the risk of unauthorized access and potential account takeovers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plane is an open-source project management tool. Prior to 1.4.0, ProjectJoinEndpoint at GET /api/workspaces/{slug}/projects/{project_id}/join/{pk}/ uses permission_classes = [AllowAny] and returns the full ProjectMemberInvite record, including its email, token, and role, to unauthenticated callers. The corresponding POST endpoint checks only whether the submitted email matches project_invite.email and does not validate the invitation token. An attacker who knows the invitation UUID can discover the invited email, register an account with that email, and accept the invitation without receiving the original invite. This issue is fixed in 1.4.0.