External risk intelligence

Plane Webhook Redirect Vulnerability Allows Internal Resource Access

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-105636

Plane is a project management tool commonly deployed as an internet-facing web application. The vulnerability exists within the application's webhook delivery mechanism, a core feature of such web services, which is reachable in standard deployments.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability in the open-source project management tool Plane. The issue allows authenticated users to create webhooks that redirect to internal network addresses, potentially exposing sensitive cloud metadata and other internal resources. While a fix is available, confirming exposure is the primary concern.

  • Redirects expose internal data.
  • Critical risk to internal resources.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can trick the Plane application into fetching sensitive internal resources by chaining a redirect vulnerability in its webhook feature. A user with the ability to create workspaces can register a webhook that points to an external server controlled by the attacker. This server then responds with a redirect to an internal network address. Plane's worker, following this redirect without proper validation, fetches data from the internal address, such as cloud metadata, and stores it where the attacker can access it.

  • Requires ability to create a workspace.
  • Triggered by a malicious webhook redirect.
  • Leads to internal data exposure.

Live Threat

Current exploitation, exposure, and threat context

A user with the ability to create a workspace could configure a webhook to redirect to an internal network resource. The Plane worker may then fetch sensitive information from these internal resources, such as cloud metadata, and store it where an attacker could retrieve it via the webhook logs API.

  • Internal network resources.
  • Webhook redirects to internal addresses.
  • Sensitive data exposure to attackers.

Operational Fix

Recommended remediation, mitigation, and detection steps

The project management tool's webhook functionality can be exploited by an attacker to access internal resources, including cloud metadata, by redirecting requests to internal addresses. Infrastructure or platform teams responsible for the Plane deployment should first identify all instances of the affected technology, determine their business criticality and network exposure, and then confirm the accountable owner. Planning for remediation should follow, prioritizing the most exposed and critical systems.

  • Platform or infrastructure teams own this.
  • Verify webhook configurations and network exposure.
  • Plan updates during scheduled maintenance.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Plane?

Plane is an open-source project management platform designed to help teams track tasks, manage workflows, and organize collaborative projects. It provides integrated tools for planning and coordination, often deployed as a web application that interacts with various external services through features like webhooks.

What does CWE-918 mean for CVE-2026-105636?

CWE-918 refers to Server-Side Request Forgery (SSRF). In this vulnerability, Plane is tricked into sending requests to unintended locations. Because the application fails to validate the final destination of a redirected web request, it can be manipulated to interact with internal network resources instead of the intended external endpoint.

How is this webhook vulnerability triggered?

The flaw is triggered when an authenticated user creates a workspace and registers a webhook pointed at an attacker-controlled server. This server issues a redirect to an internal IP address. If the webhook only checked the initial URL, it would be safe, but since it fails to inspect the final redirected destination, the worker follows the request into your private network.

Is my Plane instance at risk?

According to Halo Surface Signal, Plane is frequently deployed as an internet-facing application, increasing the likelihood that it is reachable by potential attackers. If your instance is accessible from the internet, it is at higher risk because the webhook delivery mechanism is a core, standard feature that remains active in typical deployments.

Do I need to update my Plane installation?

Yes, you should prioritize updating to version 1.4.0 or later. Before applying the update, identify where Plane is deployed in your environment and assess which workspaces are active. Coordinate with your team to plan this maintenance, focusing on securing the webhook integration path to prevent unauthorized access to internal resources.

References