CVE-2026-30242: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-30242 is a Server-Side Request Forgery (SSRF) vulnerability in Plane, an open-source project management tool, caused by incomplete IP validation in the webhook URL serializer. The flaw affects Plane versions up to and including 1.2.1 (pip package), and was disclosed on March 5, 2026, with a patch released the same day in version 1.2.3. It carries a CVSS v3.1 base score of 8.5 (High) (GitHub Advisory, Plane Advisory).

Technical details

The root cause (CWE-918) lies in plane/app/serializers/webhook.py, where the webhook URL validation only checks ip.is_loopback, failing to block other private and reserved IP ranges. An authenticated attacker with workspace ADMIN role can register a webhook pointing to internal network addresses — including 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, 0.0.0.0, and IPv4-mapped IPv6 addresses (::ffff:) — that bypass the incomplete check. When a workspace event triggers the webhook, the Plane server issues an HTTP request to the attacker-controlled internal URL and stores the full response body, which is then retrievable via the webhook logs API, enabling SSRF with full response read-back (GitHub Advisory, Plane Advisory).

Impact

A successful exploit allows an authenticated attacker to exfiltrate cloud provider instance metadata — including AWS IMDSv1 IAM credentials, GCP service account tokens, and Azure managed identity tokens — from the 169.254.169.254 link-local endpoint. Attackers can also scan and probe internal network services not exposed to the internet, with full HTTP response bodies returned through the webhook logs API, enabling data exfiltration from internal services. This can lead to privilege escalation across cloud infrastructure if harvested credentials are used to access other cloud resources (GitHub Advisory, Feedly).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires the attacker to hold a workspace ADMIN role, which limits the attack surface to privileged authenticated users. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Gain workspace ADMIN access: Obtain or compromise an account with workspace ADMIN privileges in a target Plane instance running version ≤ 1.2.1.
  2. Create a malicious webhook: Navigate to workspace settings and create a new webhook, supplying a URL targeting an internal or cloud metadata address (e.g., http://169.254.169.254/latest/meta-data/iam/security-credentials/ for AWS IMDSv1, or http://10.x.x.x:<port>/ for internal service scanning).
  3. Bypass IP validation: The serializer only checks ip.is_loopback, so private ranges such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16, and ::ffff:-mapped addresses pass validation without restriction.
  4. Trigger a webhook event: Perform any workspace action (e.g., create or update an issue) that fires the registered webhook event, causing the Plane server to issue an HTTP request to the internal URL.
  5. Retrieve the response: Access the webhook logs API to read the full HTTP response body returned from the internal service, extracting IAM credentials, tokens, or other sensitive data (GitHub Advisory, Plane Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from the Plane application server to 169.254.169.254 (AWS/GCP/Azure metadata endpoint), RFC-1918 private IP ranges (10.x.x.x, 172.16.x.x–172.31.x.x, 192.168.x.x), or 0.0.0.0; unexpected connections to internal services on non-standard ports.
  • Logs: Plane webhook delivery logs containing response bodies from internal services or cloud metadata endpoints; webhook creation events targeting private/reserved IP addresses in application audit logs.
  • Application: Webhook configurations in the Plane database with URLs resolving to private IP ranges or cloud metadata addresses; repeated webhook trigger events shortly after webhook creation by an ADMIN account.

Mitigation and workarounds

Upgrade Plane to version 1.2.3 or later, which adds validation to block webhooks pointing to reserved IP addresses (Plane Release). As a network-level workaround, implement egress filtering on the Plane application server to block outbound requests to 169.254.169.254, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, and other private/reserved ranges. Additionally, review and rotate any AWS, GCP, or Azure credentials that may have been exposed, audit webhook configurations for suspicious URLs, and enforce the principle of least privilege to limit the number of accounts with workspace ADMIN role (GitHub Advisory).

Community reactions

The vulnerability was covered by The Hacker Wire, which published a dedicated write-up on the SSRF with response read-back impact (The Hacker Wire). Social media activity was observed on Bluesky and Mastodon shortly after disclosure. Red Hat also tracked the CVE in their security advisory database (Red Hat). Community reaction was generally focused on the cloud credential exposure risk, with the Plane maintainers responding promptly by releasing a patch on the same day as disclosure.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management