← Back

CVE-2026-27949

nvd nist
Published: Apr 7, 2026Modified: Jul 24, 2026

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0.

Affected (1)

Products: Plane: Plane
1 product
Plane
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.3.0

References (1)

Source: security-advisories@github.com
Vendor Advisory

Timeline

No history available yet.