Security Advisory

CVE-2026-10850

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-17 14:39:51
Last updated 2026-06-17 15:39:40
Assigner Fluid Attacks
CVSS score 6.9
State PUBLISHED

Description

Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when creating an intake work item through the API v1 intake endpoint.