CVE-2026-105641 Overview
Plane, an open-source project management tool, ships community deployment manifests containing hardcoded SECRET_KEY and LIVE_SERVER_SECRET_KEY values. The deployments/aio/community/ and deployments/cli/community/ manifests use publicly known defaults that remain active unless operators manually override them. The top-level setup.sh script randomizes secrets only for the development Docker Compose path, leaving community deployments exposed. The issue is fixed in version 1.4.0.
Critical Impact
Knowledge of SECRET_KEY lets attackers forge Django-signed values to compromise accounts and sessions. Knowledge of LIVE_SERVER_SECRET_KEY bypasses live-service authentication on unchanged community deployments.
Affected Products
- Plane (makeplane/plane) all versions prior to 1.4.0
- deployments/aio/community/ manifest deployments
- deployments/cli/community/ manifest deployments
Discovery Timeline
- 2026-10-05 - CVE-2026-105641 published to NVD
- 2026-10-07 - Last updated in NVD database
Technical Details for CVE-2026-105641
Vulnerability Analysis
The vulnerability falls under [CWE-798] Use of Hard-coded Credentials. Plane's community deployment manifests ship with two fixed secrets: SECRET_KEY set to 60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5 and LIVE_SERVER_SECRET_KEY set to htbqvBJAgpm9bzvf3r4urJer0ENReatceh. These values are visible in the public GitHub repository and remain active across every unmodified community installation.
Django uses SECRET_KEY to sign sessions, CSRF tokens, password reset tokens, and other security-sensitive values. An attacker who knows the key can forge any of these signed values. The LIVE_SERVER_SECRET_KEY protects live-service authentication; its disclosure allows direct bypass of that control.
Root Cause
The setup.sh script generates random secrets only for the development Docker Compose path. The aio and cli community deployment manifests were never wired into that randomization logic. Operators who deploy with defaults inherit the shared, publicly known production secrets without any warning.
Attack Vector
The flaw is exploitable over the network with no authentication or user interaction. An attacker enumerates internet-facing Plane community deployments, uses the published SECRET_KEY to forge a Django session cookie or password reset token for an administrative account, and gains full application access. The same attacker can forge requests to live-service endpoints using the known LIVE_SERVER_SECRET_KEY.
# Security patch in apps/api/plane/settings/common.py
BASE_DIR = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
-# Secret Key
-SECRET_KEY = os.environ.get("SECRET_KEY", get_random_secret_key())
+_logger = logging.getLogger("plane")
+
+# Secret Key — use `or` so an explicitly empty env var is treated the same as unset,
+# falling back to a random key rather than passing "" to Django (GHSA-cmwv-pjmw-8483).
+SECRET_KEY = os.environ.get("SECRET_KEY") or get_random_secret_key()
+# Refuse to run silently with a publicly-known or placeholder SECRET_KEY.
+_INSECURE_SECRET_KEYS = {
+ "60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5", # old publicly-known default
+ "change-this-key-on-deployment", # placeholder shipped in community templates
+}
+if SECRET_KEY in _INSECURE_SECRET_KEYS:
+ _logger.critical(
+ "SECURITY: SECRET_KEY is set to a known insecure or placeholder value. "
+ "This makes your installation vulnerable to session forgery, CSRF bypass, and "
+ "password-reset token forging. Set a unique SECRET_KEY before deploying to production."
+ )
Source: GitHub Commit 1acc69e
Detection Methods for CVE-2026-105641
Indicators of Compromise
- Presence of SECRET_KEY=60gp0byfz2dvffa45cxl20p1scy9xbpf6d8c5y0geejgkyp1b5 in running Plane container environment variables.
- Presence of LIVE_SERVER_SECRET_KEY=htbqvBJAgpm9bzvf3r4urJer0ENReatceh in deployed configuration.
- Unexpected administrative sessions or password-reset events in Plane audit logs with no corresponding user action.
Detection Strategies
- Inspect container environment and Compose files for the two publicly known default values.
- Compare the Plane deployment version against 1.4.0 and verify which community manifest was used.
- Review authentication logs for session cookies validated against the default SECRET_KEY and any live-service calls using the default LIVE_SERVER_SECRET_KEY.
Monitoring Recommendations
- Alert on new admin logins and privilege changes in Plane that lack a prior interactive login event.
- Monitor outbound traffic from Plane hosts for unexpected API calls to internal live-service endpoints.
- Track configuration drift on deployment manifests to catch reintroduction of hardcoded secrets.
How to Mitigate CVE-2026-105641
Immediate Actions Required
- Upgrade Plane to version 1.4.0 or later, which removes the hardcoded defaults and auto-generates secrets on first boot.
- Rotate both SECRET_KEY and LIVE_SERVER_SECRET_KEY on every existing community deployment, even after patching.
- Invalidate all active sessions and force password resets after secret rotation.
- Review audit logs for signs of forged sessions or unauthorized live-service calls prior to remediation.
Patch Information
The fix is included in Plane v1.4.0. See the GitHub Release v1.4.0, Pull Request #9291, and Security Advisory GHSA-cmwv-pjmw-8483. The patch falls back to get_random_secret_key() when SECRET_KEY is unset or empty and emits a critical log entry if a known insecure value is detected.
Workarounds
- Explicitly set strong, unique values for SECRET_KEY and LIVE_SERVER_SECRET_KEY via environment variables before starting Plane.
- Restrict network exposure of community deployments to trusted networks until the upgrade is applied.
- Place Plane behind an authenticating reverse proxy to limit anonymous access to signed endpoints.
# Generate a strong SECRET_KEY and export before deployment
export SECRET_KEY="$(python3 -c 'from django.utils.crypto import get_random_secret_key; print(get_random_secret_key())')"
export LIVE_SERVER_SECRET_KEY="$(openssl rand -base64 48)"
# Verify defaults are not present in the running container
docker exec plane-api printenv SECRET_KEY LIVE_SERVER_SECRET_KEY
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.