
#ExploitGrid Daily #Digest 🚨 Top CVEs: CVE-2026-100103 (CVSS: 10) Perfoce CVE-2026-105284 (CVSS: 10) Totolink CVE-2026-105285 (CVSS: 10) Totolink CVE-2026-105636 (CVSS: 9.9) makeplane CVE-2026-105691 (CVSS: 9.9) Penpot ..🧵👇
Signal is active with 3 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Plane is an open-source project management tool. Prior to 1.4.0, the webhook delivery task in apps/api/plane/bgtasks/webhook_task.py calls requests.post() without allow_redirects=False and does not validate redirect targets. validate_url() blocks private, loopback, link-local, and reserved addresses in the original webhook URL, but the final URL reached after one or more redirects is not checked. A user who can create a workspace can register a webhook pointing to an attacker-controlled public endpoint that returns a 302 redirect to an internal address. The Plane worker then fetches internal resources, including cloud metadata, and stores the response body in webhook_logs, where the attacker can retrieve it through the workspace webhook-logs API. This issue is fixed in 1.4.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

#ExploitGrid Daily #Digest 🚨 Top CVEs: CVE-2026-100103 (CVSS: 10) Perfoce CVE-2026-105284 (CVSS: 10) Totolink CVE-2026-105285 (CVSS: 10) Totolink CVE-2026-105636 (CVSS: 9.9) makeplane CVE-2026-105691 (CVSS: 9.9) Penpot ..🧵👇

├ CVE-2026-105636 — Plane (makeplane) · SSRF via webhook redirect └ CVE-2026-105691 — Penpot · Auth'd OS command injection (SVG exporter)

[CVE] CVE-2026-105636 [HIGH PRIORITY] CVSS: 9.9 | Vendor: #makeplane #Plane: SSRF via HTTP redirect in webhook delivery (allow_redirects not set) 🔗 https://exploitgrid.net/cve/CVE-2026-105636