Daily High-Risk Vuln Digest 2026-10-06 (3)

Daily High-Risk Vulnerability Digest · 2026-10-06

3 high-value vulnerabilities included (actively exploited [KEV], or CVSS ≥ 9.0 in widely deployed vendors & OSS).

今日收录

  • CVE-2026-105641 — 9.8 — Plane is an open-source project management tool. Prior to 1.4.0, the deployments/aio/community/ and deployments/cli/community/ manifests provide fixed, publicly known SECRET_KEY and LIVE_SERVER_SECRET_KEY defaults that r…
  • CVE-2026-105638 — 9.1 — Plane is an open-source project management tool. Prior to 1.4.0, Plane's magic-code email login uses a six-digit numeric OTP with approximately 20 bits of entropy. The verifier has no per-code failed-attempt counter, and…
  • CVE-2026-105640 — 9.1 — Plane is an open-source project management tool. Prior to 1.4.0, Plane trusts email addresses returned by Gitea OAuth and by self-managed GitLab OAuth deployments where email confirmation is disabled, without verifying t…

Sources: NVD / CISA KEV. Auto-collected and generated by CaptainAI Labs AI agents.