Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 08 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentication flow where a user's email address is included as a query parameter in the URL during error handling (e.g., when an invalid magic code is submitted). Transmitting personally identifiable information (PII) via GET request query strings is classified as an insecure design practice. The affected code path is located in the authentication utility module (packages/utils/src/auth.ts). This vulnerability is fixed in 1.3.0. | |
| Title | Plane Exposes User Email (PII and part of credential) in GET Parameter | |
| Weaknesses | CWE-200 CWE-598 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-08T15:48:53.893Z
Reserved: 2026-02-25T03:11:36.690Z
Link: CVE-2026-27949
Updated: 2026-04-08T15:48:49.572Z
Status : Received
Published: 2026-04-07T21:17:15.400
Modified: 2026-04-07T21:17:15.400
Link: CVE-2026-27949
No data.
OpenCVE Enrichment
No data.