Nixpkgs security tracker

Try the new UI
Login with GitHub

Suggestions search

With package: invoiceplane

Found 34 matching suggestions

View:
Compact
Detailed
Untriaged
Permalink CVE-2026-85274
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): None (N)
  • User Interaction (UI): Required (R)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): None (N)
  • Integrity (I): High (H)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): None (N)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): None (N)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): None (N)
created 4 days, 2 hours ago Activity log
  • Created suggestion
InvoicePlane: Recurring Invoice State Change via GET Request Without CSRF Protection

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Recurring::stop() as a state-changing GET route without CSRF token validation. When an authenticated administrator loads attacker-controlled content that requests /invoices/recurring/stop/{id}, the application stops the selected recurring invoice. An attacker can target multiple identifiers to interrupt recurring billing and cause financial loss. This issue is fixed in version 1.7.2.

Affected products

InvoicePlane
  • ==< 1.7.2

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

Package maintainers

Untriaged
Permalink CVE-2026-33639
7.2 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 days, 2 hours ago Activity log
  • Created suggestion
InvoicePlane permits DDL injection through tax_rate_decimal_places

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane interpolates the administrator-controlled tax_rate_decimal_places setting into an ALTER TABLE statement for ip_tax_rates in Settings::index() without strict integer validation. A crafted setting value can add clauses to the schema-changing statement and remove or alter required database columns. The resulting schema corruption can permanently modify financial data structures and make the application unavailable. This vulnerability is fixed in 1.7.2.

Affected products

InvoicePlane
  • ==< 1.7.2

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

Package maintainers

Untriaged
Permalink CVE-2026-49850
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 days, 2 hours ago Activity log
  • Created suggestion
InvoicePlane: Missing CSRF Protection on State-Changing delete Actions

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane exposes Invoices::delete() and Invoices::delete_invoice_tax() as state-changing routes without requiring POST and validating a CSRF token. When an authenticated administrator loads attacker-controlled content that requests an affected route, the application can delete an invoice or invoice tax record. The cross-origin action can remove financial data without the administrator's intent. This issue is fixed in version 1.7.2.

Affected products

InvoicePlane
  • ==< 1.7.2

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

Package maintainers

Untriaged
Permalink CVE-2026-85293
4.8 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): High (H)
  • User Interaction (UI): Required (R)
  • Scope (S): Changed (C)
  • Confidentiality (C): Low (L)
  • Integrity (I): Low (L)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): High (H)
  • Modified User Interaction (MUI): Required (R)
  • Modified Confidentiality (MC): Low (L)
  • Modified Scope (MS): Changed (C)
  • Modified Integrity (MI): Low (L)
  • Modified Availability (MA): None (N)
created 4 days, 2 hours ago Activity log
  • Created suggestion
InvoicePlane: Stored Cross-Site Scripting (XSS) via Client Email in Invoice and Quote Mailer Forms

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-beta-1, InvoicePlane stores client_email values without enforcing email syntax and renders them unescaped inside double-quoted value attributes in the invoice mailer form and quote mailer form. An administrator who can edit a client can store attribute-breaking input, and, when the mailer is configured, JavaScript executes when another authenticated administrator opens the related mailer page. The script runs in the InvoicePlane origin and can perform same-origin actions with the victim's session. This issue is fixed in version 1.7.2.

Affected products

InvoicePlane
  • ==< 1.7.2

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

Package maintainers

Untriaged
Permalink CVE-2026-50547
7.5 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): High (H)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): High (H)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): High (H)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): High (H)
created 4 days, 2 hours ago Activity log
  • Created suggestion
InvoicePlane permits local file inclusion through the e-invoice XML configuration identifier

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, InvoicePlane's Invoices::generate_xml() method appends a database-derived xml_id to the XMLconfigs helper directory and includes the resulting PHP path without validating the identifier. A low-privileged attacker who can influence the e-invoice configuration can use traversal sequences to include an existing PHP file. The standalone advisory establishes local file inclusion; code execution requires a separate file-upload or file-write primitive. This issue is fixed in version 1.7.2.

Affected products

InvoicePlane
  • ==< 1.7.2

Matching in nixpkgs

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

Package maintainers

Untriaged
Permalink CVE-2026-86174
5.3 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Vulnerable System Impact Confidentiality (VC): None (N)
  • Vulnerable System Impact Integrity (VI): Low (L)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): None (N)
  • Subsequent System Impact Integrity (SI): None (N)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Vulnerable System Impact Confidentiality (MVC): None (N)
  • Modified Vulnerable System Impact Integrity (MVI): Low (L)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
  • Modified Subsequent System Impact Integrity (MSI): Negligible (N)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 weeks, 3 days ago Activity log
  • Created suggestion
Plane through 1.4.2 Arbitrary Comment Write via Public Deploy Board

Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrary issues across workspaces by supplying an issue_id parameter to the public deploy-board comment endpoint.

Affected products

plane
  • =<1.4.2

Matching in nixpkgs

pkgs.xplanet

Renders an image of the earth or other planets into the X root window

  • nixos-unstable -
    • nixos-unstable-small 1.3.1
  • nixos-26.05 -
    • nixos-26.05-small 1.3.1

pkgs.freeplane

Mind-mapping software

  • nixos-unstable -
  • nixos-26.05 -

pkgs.headplane

Feature-complete Web UI for Headscale

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.m2-planet

PLAtform NEutral Transpiler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane

NGINX configuration file parser and builder

  • nixos-unstable -
    • nixos-unstable-small 0.5.8
  • nixos-26.05 -
    • nixos-26.05-small 0.5.8

pkgs.microplane

CLI tool to make git changes across many repos

  • nixos-unstable -
  • nixos-26.05 -

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

pkgs.m2-mesoplanet

Macro Expander Saving Our m2-PLANET

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane-cli

Utility to make using Crossplane easier

  • nixos-unstable -
    • nixos-unstable-small 2.5.0
  • nixos-26.05 -
    • nixos-26.05-small 2.3.0

pkgs.headplane-agent

Optional sidecar process providing additional features for headplane

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.biplanes-revival

Old cellphone arcade recreated for PC

  • nixos-unstable -
    • nixos-unstable-small 1.2.1
  • nixos-26.05 -
    • nixos-26.05-small 1.2.1
Untriaged
created 2 months, 1 week ago Activity log
  • Created suggestion
CVE-2026-15342

Plane contains a multi‑tenant authorization flaw in its asset‑management API that allows authenticated users from one workspace to access, delete, or duplicate assets belonging to another workspace by providing only the victim workspace slug and asset ID. The affected endpoints return presigned file URLs and enable destructive or duplicative actions without verifying that the requester is a member of the targeted workspace. This enables cross‑tenant data exposure, data deletion, and persistent exfiltration of files into an attacker‑controlled workspace.

Affected products

Plane
  • =<1.3.0

Matching in nixpkgs

pkgs.xplanet

Renders an image of the earth or other planets into the X root window

  • nixos-unstable -
    • nixos-unstable-small 1.3.1
  • nixos-26.05 -
    • nixos-26.05-small 1.3.1

pkgs.freeplane

Mind-mapping software

  • nixos-unstable -
  • nixos-26.05 -

pkgs.headplane

Feature-complete Web UI for Headscale

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.m2-planet

PLAtform NEutral Transpiler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane

NGINX configuration file parser and builder

  • nixos-unstable -
    • nixos-unstable-small 0.5.8
  • nixos-26.05 -
    • nixos-26.05-small 0.5.8

pkgs.microplane

CLI tool to make git changes across many repos

  • nixos-unstable -
  • nixos-26.05 -

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

pkgs.m2-mesoplanet

Macro Expander Saving Our m2-PLANET

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane-cli

Utility to make using Crossplane easier

  • nixos-unstable -
    • nixos-unstable-small 2.5.0
  • nixos-26.05 -
    • nixos-26.05-small 2.3.0

pkgs.headplane-agent

Optional sidecar process providing additional features for headplane

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.biplanes-revival

Old cellphone arcade recreated for PC

  • nixos-unstable -
    • nixos-unstable-small 1.2.1
  • nixos-26.05 -
    • nixos-26.05-small 1.2.1
Untriaged
Permalink CVE-2026-10850
6.9 MEDIUM
  • CVSS version (CVSS): 4.0
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Attack Requirement (AT): None (N)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): Passive (P)
  • Vulnerable System Impact Confidentiality (VC): High (H)
  • Vulnerable System Impact Integrity (VI): None (N)
  • Vulnerable System Impact Availability (VA): None (N)
  • Subsequent System Impact Confidentiality (SC): Low (L)
  • Subsequent System Impact Integrity (SI): Low (L)
  • Subsequent System Impact Availability (SA): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Attack Requirement (MAT): None (N)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): Passive (P)
  • Modified Vulnerable System Impact Confidentiality (MVC): High (H)
  • Modified Vulnerable System Impact Integrity (MVI): None (N)
  • Modified Vulnerable System Impact Availability (MVA): None (N)
  • Modified Subsequent System Impact Confidentiality (MSC): Low (L)
  • Modified Subsequent System Impact Integrity (MSI): Low (L)
  • Modified Subsequent System Impact Availability (MSA): Negligible (N)
  • Safety (S): Not Defined (X)
  • Automatable (AU): Not Defined (X)
  • Recovery (R): Not Defined (X)
  • Value Density (V): Not Defined (X)
  • Vulnerability Response Effort (RE): Not Defined (X)
  • Provider Urgency (U): Not Defined (X)
  • Confidentiality Req. (CR): Not Defined (X)
  • Integrity Req. (IR): Not Defined (X)
  • Availability Req. (AR): Not Defined (X)
  • Exploit Maturity (E): Not Defined (X)
created 3 months, 1 week ago Activity log
  • Created suggestion
Plane 1.3.1 - Stored XSS in intake issue description_html

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.

Affected products

Plane
  • ==1.3.1

Matching in nixpkgs

pkgs.xplanet

Renders an image of the earth or other planets into the X root window

  • nixos-unstable -
    • nixos-unstable-small 1.3.1
  • nixos-26.05 -
    • nixos-26.05-small 1.3.1

pkgs.freeplane

Mind-mapping software

  • nixos-unstable -
  • nixos-26.05 -

pkgs.headplane

Feature-complete Web UI for Headscale

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2

pkgs.m2-planet

PLAtform NEutral Transpiler

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane

NGINX configuration file parser and builder

  • nixos-unstable -
    • nixos-unstable-small 0.5.8
  • nixos-26.05 -
    • nixos-26.05-small 0.5.8

pkgs.microplane

CLI tool to make git changes across many repos

  • nixos-unstable -
  • nixos-26.05 -

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable -
    • nixos-unstable-small 1.7.2
  • nixos-26.05 -
    • nixos-26.05-small 1.7.2

pkgs.m2-mesoplanet

Macro Expander Saving Our m2-PLANET

  • nixos-unstable -
  • nixos-26.05 -

pkgs.crossplane-cli

Utility to make using Crossplane easier

  • nixos-unstable -
    • nixos-unstable-small 2.5.0
  • nixos-26.05 -
    • nixos-26.05-small 2.3.0

pkgs.headplane-agent

Optional sidecar process providing additional features for headplane

  • nixos-unstable -
    • nixos-unstable-small 0.7.1
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3

pkgs.biplanes-revival

Old cellphone arcade recreated for PC

  • nixos-unstable -
    • nixos-unstable-small 1.2.1
  • nixos-26.05 -
    • nixos-26.05-small 1.2.1
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-46558
8.3 HIGH
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): High (H)
  • Availability (A): Low (L)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): High (H)
  • Modified Availability (MA): Low (L)
updated 3 months, 2 weeks ago by @LeSuisse Activity log
  • Created suggestion
  • @LeSuisse dismissed (not in Nixpkgs)
Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces

Plane is an open-source project management tool. Prior to version 1.3.1, there is a cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces. This issue has been patched in version 1.3.1.

Affected products

plane
  • ==< 1.3.1

Matching in nixpkgs

pkgs.xplanet

Renders an image of the earth or other planets into the X root window

  • nixos-unstable 1.3.1
    • nixpkgs-unstable 1.3.1
    • nixos-unstable-small 1.3.1
  • nixos-26.05 -
    • nixos-26.05-small 1.3.1
    • nixpkgs-26.05-darwin 1.3.1

pkgs.headplane

Feature-complete Web UI for Headscale

  • nixos-unstable 0.6.2
    • nixpkgs-unstable 0.6.2
    • nixos-unstable-small 0.6.2
  • nixos-26.05 -
    • nixos-26.05-small 0.6.2
    • nixpkgs-26.05-darwin 0.6.2

pkgs.crossplane

NGINX configuration file parser and builder

  • nixos-unstable 0.5.8
    • nixpkgs-unstable 0.5.8
    • nixos-unstable-small 0.5.8
  • nixos-26.05 -
    • nixos-26.05-small 0.5.8
    • nixpkgs-26.05-darwin 0.5.8

pkgs.microplane

CLI tool to make git changes across many repos

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

  • nixos-unstable 1.7.1
    • nixpkgs-unstable 1.7.1
    • nixos-unstable-small 1.7.1
  • nixos-26.05 -
    • nixos-26.05-small 1.7.1
    • nixpkgs-26.05-darwin 1.7.1

pkgs.crossplane-cli

Utility to make using Crossplane easier

  • nixos-unstable 2.3.0
    • nixpkgs-unstable 2.3.0
    • nixos-unstable-small 2.3.0
  • nixos-26.05 -
    • nixos-26.05-small 2.3.0
    • nixpkgs-26.05-darwin 2.3.0

pkgs.headplane-agent

Optional sidecar process providing additional features for headplane

  • nixos-unstable 0.6.3
    • nixpkgs-unstable 0.6.3
    • nixos-unstable-small 0.6.3
  • nixos-26.05 -
    • nixos-26.05-small 0.6.3
    • nixpkgs-26.05-darwin 0.6.3
Dismissed
(not in Nixpkgs)
Permalink CVE-2026-40102
6.5 MEDIUM
  • CVSS version (CVSS): 3.1
  • Attack Vector (AV): Network (N)
  • Attack Complexity (AC): Low (L)
  • Privileges Required (PR): Low (L)
  • User Interaction (UI): None (N)
  • Scope (S): Unchanged (U)
  • Confidentiality (C): High (H)
  • Integrity (I): None (N)
  • Availability (A): None (N)
  • Modified Attack Vector (MAV): Network (N)
  • Modified Attack Complexity (MAC): Low (L)
  • Modified Privileges Required (MPR): Low (L)
  • Modified User Interaction (MUI): None (N)
  • Modified Confidentiality (MC): High (H)
  • Modified Scope (MS): Unchanged (U)
  • Modified Integrity (MI): None (N)
  • Modified Availability (MA): None (N)
updated 4 months ago by @06kellyjac Activity log
  • Created suggestion
  • @06kellyjac ignored package m2-planet
  • @06kellyjac dismissed (not in Nixpkgs)
Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without validation (unlike the regular AnalyticsEndpoint, which checks against an allowlist), causing ORM Field Reference Injection. An authenticated workspace MEMBER can send GET /api/workspaces/<slug>/saved-analytic-view/<analytic_id>/ with a crafted segment value that is forwarded into build_graph_plot() and traverses foreign-key relationships (e.g. workspace__owner__password) before being projected via .values("dimension", "segment"), returning the referenced field values directly in the JSON response. This exposes sensitive data such as bcrypt password hashes, API tokens, and related users' email addresses, making it a stronger primitive than the related order_by injection where values are only leaked through ordering. This issue has been fixed in version 1.3.1.

Affected products

plane
  • ==< 1.3.1

Matching in nixpkgs

pkgs.xplanet

Renders an image of the earth or other planets into the X root window

pkgs.headplane

Feature-complete Web UI for Headscale

pkgs.crossplane

NGINX configuration file parser and builder

pkgs.microplane

CLI tool to make git changes across many repos

pkgs.invoiceplane

Self-hosted open source application for managing your invoices, clients and payments

pkgs.headplane-agent

Optional sidecar process providing additional features for headplane

Ignored packages (1)