CVE 2 LOW

Plane Exposes User Email (PII and part of credential) in GET Parameter_CVE-2026-27949

2 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N

Description

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0.

Basic Information

ID CVE-2026-27949
Source GitHub_M
Published Apr 7, 2026 at 20:26
Modified Apr 8, 2026 at 15:48

Affected Product

Vendor makeplane
Product plane
Version < 1.3.0
Affected Versions makeplane plane < 1.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.