CVE-2026-105636 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-105636 requires immediate attention.

· 7 min read

Executive Summary

CVE-2026-105636 is a critical SSRF vulnerability in Plane’s webhook delivery worker, affecting versions prior to 1.4.0. A workspace user can create a webhook that points to an attacker-controlled public URL, which then redirects the worker to an internal address such as cloud metadata or private services. Plane follows the redirect, fetches the internal response, and stores the body in webhook_logs, where it can be retrieved through the workspace webhook-logs API.

This is high risk for small teams because it can expose secrets, instance metadata, internal admin panels, and service credentials with little attacker effort. No exploitation in the wild is known and it is not in KEV, but the severity is CRITICAL (CVSS 9.9). Upgrade to 1.4.0 immediately.

Immediate Action

  • Patch now: upgrade Plane to 1.4.0 or later as soon as possible.
  • Block webhook creation for untrusted users until patched, if your workflow allows it.
  • Restrict worker egress so the Plane worker cannot reach internal IP ranges, metadata endpoints, or private DNS zones.
  • Review webhook logs for suspicious responses, especially anything resembling credentials, tokens, or metadata.
  • Rotate secrets if the worker could reach cloud metadata or internal services before patching.
  • Vendor advisory: Plane security advisory / release notes

Affected Versions

  • plane<1.4.0 vulnerable
  • plane@1.4.0+ safe
  • apps/api/plane/bgtasks/webhook_task.py in affected releases follows redirects without validating the final destination

Resolution Guide

Preferred fix: upgrade Plane to 1.4.0 or later. If you deploy via containers, update the image tag and redeploy. If you package Plane in your own build, pin the fixed release and rebuild.

# Docker / containerized deployment
docker pull plane:1.4.0
docker stop plane
docker rm plane
docker run -d --name plane plane:1.4.0
# npm / yarn / pnpm (if Plane is vendored or wrapped in a JS deployment)
npm install plane@1.4.0
yarn add plane@1.4.0
pnpm add plane@1.4.0
# pip / pipx (if you install from Python packages or a wrapper)
pip install --upgrade plane==1.4.0
pipx upgrade plane
# Maven / Gradle (if Plane is consumed as a dependency in a Java wrapper)
mvn versions:use-latest-releases -Dincludes=io.plane:plane
./gradlew dependencyUpdates
# then pin to 1.4.0 or later in your build files
# apt / yum (if your environment ships a package)
sudo apt-get update && sudo apt-get install --only-upgrade plane
sudo yum update plane

Hardening while you patch:

# Example: block worker access to metadata and RFC1918 ranges at the network layer
# Replace with your firewall / security group / egress policy tooling
DENY 169.254.169.254/32
DENY 127.0.0.0/8
DENY 10.0.0.0/8
DENY 172.16.0.0/12
DENY 192.168.0.0/16
DENY 100.64.0.0/10
DENY ::1/128
DENY fc00::/7
# If you can disable webhook delivery temporarily, do so until patched
# TODO: replace with your Plane config flag / env var if available
export TODO_DISABLE_WEBHOOK_DELIVERY=true

Code fix example: the worker should refuse redirects and validate the final destination before fetching. A minimal pattern is:

response = requests.post(
    url,
    json=payload,
    timeout=10,
    allow_redirects=False,
)

if 300 <= response.status_code < 400:
    raise ValueError("Redirects are not allowed for webhook delivery")

validate_url(url)  # validate the actual target being fetched

If you maintain a fork, also ensure any redirect-following HTTP client behavior is disabled for webhook delivery paths, and re-check the resolved destination after every redirect hop.

Detection & Verification

Check your version:

# Docker
docker image inspect plane:latest --format '{{.RepoTags}}'

# If installed from source or a package
grep -R "version" -n . | head
python -c "import plane; print(getattr(plane, '__version__', 'unknown'))"

Look for the vulnerable code path:

grep -R "requests.post(" -n apps/api/plane/bgtasks/webhook_task.py
grep -R "allow_redirects" -n apps/api/plane/bgtasks/webhook_task.py
grep -R "validate_url" -n apps/api/plane/bgtasks/webhook_task.py

What to verify after upgrading:

# Confirm the fixed release is deployed
docker exec plane sh -lc 'python -c "import plane; print(getattr(plane, \"__version__\", \"unknown\"))"'

# Confirm webhook delivery no longer follows redirects
# Use a test webhook endpoint that returns 302 to an internal address
# Expected result: delivery fails, and no internal response body is stored

Dependency audit: run your normal software inventory and search for Plane versions below 1.4.0.

# Examples
pip freeze | grep -i plane
npm ls plane
yarn why plane
pnpm why plane

Risk and Impact

This flaw can turn a normal webhook feature into an internal network probe. An attacker with workspace creation rights may be able to pull cloud metadata, internal service responses, or other sensitive data through the Plane worker and then read it back from webhook logs.

The likely blast radius includes credentials, temporary cloud tokens, internal endpoints, and data from services reachable only from the Plane worker. For small teams, that can mean full environment exposure if the worker runs with broad network access or cloud permissions.

Keep reading