Skip to content

IDOR : Unauthenticated Asset Access

Low
mguptahub published GHSA-gcpp-8php-g682 Sep 28, 2026

Software

makeplane/plane

Affected versions

<= 1.3.1

Patched versions

1.4.0

Description

Summary

Presigned S3 URL in upload Avatar feature returned for victim's asset with no authentication.

Details

plane/app/views/asset/v2.py:452 — permission_classes = [AllowAny]
Issue is here:
GET /api/assets/v2/static/beb4da02-b0ee-4d2a-9258-4768c5c5c933/
the request has zero cookies, zero auth header for this request

PoC

Login to the application and upload Avatar ( image).
Copy link to this image and open it in a different browser.
The url reveals X-Amz-Credential=access-key, X-Amz-Signature, X-Amz-Expires without proper authorisation.

Impact

Anyone on the internet, can access any asset UUID. No account needed at all.

Severity

Low

CVE ID

CVE-2026-102987

Weaknesses

No CWEs

Credits