No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Makeplane
Makeplane plane |
|
| Vendors & Products |
Makeplane
Makeplane plane |
Wed, 08 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0. | |
| Title | Plane Exposes User Email (PII and part of credential) in GET Parameter | |
| Weaknesses | CWE-200 CWE-598 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T15:48:53.893Z
Reserved: 2026-02-25T03:11:36.690Z
Link: CVE-2026-27949
Updated: 2026-04-08T15:48:49.572Z
Status : Awaiting Analysis
Published: 2026-04-07T21:17:15.400
Modified: 2026-04-08T21:27:00.663
Link: CVE-2026-27949
No data.
OpenCVE Enrichment
Updated: 2026-04-08T19:45:47Z