
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30242 is a Server-Side Request Forgery (SSRF) vulnerability in Plane, an open-source project management tool, caused by incomplete IP validation in the webhook URL serializer. The flaw affects Plane versions up to and including 1.2.1 (pip package), and was disclosed on March 5, 2026, with a patch released the same day in version 1.2.3. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, Plane Advisory).
The root cause (CWE-918) lies in plane/app/serializers/webhook.py, where the webhook URL validation only checks ip.is_loopback, failing to block other private and reserved IP ranges. An authenticated attacker with workspace ADMIN role can register a webhook pointing to internal network addresses — including 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, 0.0.0.0, and IPv4-mapped IPv6 addresses (::ffff:) — that bypass the incomplete check. When a workspace event triggers the webhook, the Plane server issues an HTTP request to the attacker-controlled internal URL and stores the full response body, which is then retrievable via the webhook logs API, enabling SSRF with full response read-back (GitHub Advisory, Plane Advisory).
A successful exploit allows an authenticated attacker to exfiltrate cloud provider instance metadata — including AWS IMDSv1 IAM credentials, GCP service account tokens, and Azure managed identity tokens — from the 169.254.169.254 link-local endpoint. Attackers can also scan and probe internal network services not exposed to the internet, with full HTTP response bodies returned through the webhook logs API, enabling data exfiltration from internal services. This can lead to privilege escalation across cloud infrastructure if harvested credentials are used to access other cloud resources (GitHub Advisory, Feedly).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires the attacker to hold a workspace ADMIN role, which limits the attack surface to privileged authenticated users. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
http://169.254.169.254/latest/meta-data/iam/security-credentials/ for AWS IMDSv1, or http://10.x.x.x:<port>/ for internal service scanning).ip.is_loopback, so private ranges such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, and ::ffff:-mapped addresses pass validation without restriction.169.254.169.254 (AWS/GCP/Azure metadata endpoint), RFC-1918 private IP ranges (10.x.x.x, 172.16.x.x–172.31.x.x, 192.168.x.x), or 0.0.0.0; unexpected connections to internal services on non-standard ports.Upgrade Plane to version 1.2.3 or later, which adds validation to block webhooks pointing to reserved IP addresses (Plane Release). As a network-level workaround, implement egress filtering on the Plane application server to block outbound requests to 169.254.169.254, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and other private/reserved ranges. Additionally, review and rotate any AWS, GCP, or Azure credentials that may have been exposed, audit webhook configurations for suspicious URLs, and enforce the principle of least privilege to limit the number of accounts with workspace ADMIN role (GitHub Advisory).
The vulnerability was covered by The Hacker Wire, which published a dedicated write-up on the SSRF with response read-back impact (The Hacker Wire). Social media activity was observed on Bluesky and Mastodon shortly after disclosure. Red Hat also tracked the CVE in their security advisory database (Red Hat). Community reaction was generally focused on the cloud credential exposure risk, with the Plane maintainers responding promptly by releasing a patch on the same day as disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."