CVE-2026-104960

CVE-2026-104960 published: Plane is an open-source project management tool. Prior to 1.4.0, Plane exposes the workspace-scoped GET /api/assets/v2/workspaces/{workspace_slug}/download/{asset_id}/ endpoint for project-bound FileAsset objects without enforcing access to the asset's owni...

View full NVD advisory → ← Back to CVE watch