binarybeachio fork of makeplane/plane � Zitadel OIDC repurposing of /auth/github/. See BINARYBEACHIO.md.
Find a file
sriram veeraghanta 63fac3b8c4
fix: validate redirects in favicon fetching to prevent SSRF (#8858)
* fix: validate redirects in favicon fetching to prevent SSRF

The previous SSRF fix (GHSA-jcc6-f9v6-f7jw) only validated redirects for
the main page URL but not for the favicon fetch path. An attacker could
craft an HTML page with a favicon link that redirects to a private IP,
bypassing the IP validation and leaking internal network data as base64.

Extract a reusable `safe_get()` function that validates every redirect hop
against private/internal IPs and use it for both page and favicon fetches.

Resolves: GHSA-9fr2-pprw-pp9j

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

* fix: address PR review feedback for SSRF favicon fix

- Fix off-by-one in redirect limit: only raise RuntimeError when the
  response is still a redirect after MAX_REDIRECTS hops, not when the
  final response is a successful 200
- Return final URL from safe_get() so favicon href resolution uses the
  correct origin after redirects instead of the original URL
- Add unit tests for validate_url_ip and safe_get covering private IP
  blocking, redirect-following, and redirect limit enforcement

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-04-06 16:04:43 +05:30
.github chore: adding traget commit sha for the github release 2026-03-31 17:54:47 +05:30
.husky fix: eslint (#8185) 2025-12-05 16:03:51 +05:30
.idx chore: add IDX configuration so anyone can edit the project from idx.google.com (#5398) 2024-08-28 13:52:25 +05:30
apps fix: validate redirects in favicon fetching to prevent SSRF (#8858) 2026-04-06 16:04:43 +05:30
deployments [INFRA-351] fix: correct directory and command for space program in supervisor.conf #8838 2026-03-31 18:53:51 +05:30
docs fix: replace eslint with oxlint (#8677) 2026-03-03 00:46:05 +05:30
packages chore: version bump 2026-03-31 17:09:35 +05:30
.dockerignore [WEB-5040] feat: admin react-router migration (#7922) 2025-11-06 13:39:35 +05:30
.env.example [INFRA-209] Remove nginx related configurations from plane community (#7406) 2025-07-14 16:38:27 +05:30
.gitattributes fix: Local Setup on Windows (#5539) 2024-09-10 17:28:18 +05:30
.gitignore [WEB-5602] feat: new design system (#8220) 2025-12-12 20:50:14 +05:30
.mise.toml [WEB-5048] chore: implements esm exports for all packages (#7816) 2025-10-06 21:01:32 +05:30
.npmrc fix: updated npmrc with hoist patterns (#8271) 2025-12-09 16:32:49 +05:30
.oxfmtrc.json chore: replace prettier with oxfmt (#8676) 2026-03-02 20:40:50 +05:30
.oxlintrc.json fix: disable react-in-jsx-scope rule in oxlint config (#8682) 2026-03-04 13:36:44 +05:30
.prettierignore fix: eslint (#8185) 2025-12-05 16:03:51 +05:30
AGENTS.md fix: replace eslint with oxlint (#8677) 2026-03-03 00:46:05 +05:30
CODE_OF_CONDUCT.md chore: updated the contact email (#2605) 2023-11-02 16:27:23 +05:30
CODEOWNERS fix: eslint (#8185) 2025-12-05 16:03:51 +05:30
CONTRIBUTING.md [WEB-6420] chore: migrate community references from Discord to Forum (#8657) 2026-03-04 13:08:36 +05:30
COPYRIGHT.txt chore: add copyright (#8584) 2026-01-27 13:54:22 +05:30
COPYRIGHT_CHECK.md chore: add copyright (#8584) 2026-01-27 13:54:22 +05:30
docker-compose-local.yml fix: removed unused files 2026-03-25 02:04:20 +05:30
docker-compose.yml Update docker-compose.yml for valkey security patch (#7926) 2025-10-09 17:15:49 +05:30
LICENSE.txt LICENSE change for Plane 2023-06-19 18:47:39 +05:30
package.json chore: version bump 2026-03-31 17:09:35 +05:30
pnpm-lock.yaml chore(deps): replace dotenvx with dotenv and update overrides (#8832) 2026-03-31 16:55:17 +05:30
pnpm-workspace.yaml chore(deps): replace dotenvx with dotenv and update overrides (#8832) 2026-03-31 16:55:17 +05:30
README.md [WEB-6420] chore: migrate community references from Discord to Forum (#8657) 2026-03-04 13:08:36 +05:30
SECURITY.md Updated SECURITY.md (#5737) 2024-10-03 14:09:01 +05:30
setup.sh feat: migrate to pnpm from yarn (#7593) 2025-08-19 20:06:42 +05:30
turbo.json chore(deps): minimatch and rollup package vulnerabilities (#8675) 2026-03-03 01:26:29 +05:30



Plane Logo

Modern project management for all teams

WebsiteForumTwitterDocumentation

Plane Screens

Meet Plane, an open-source project management tool to track issues, run sprints cycles, and manage product roadmaps without the chaos of managing the tool itself. 🧘‍♀️

Plane is evolving every day. Your suggestions, ideas, and reported bugs help us immensely. Do not hesitate to join in the conversation on Forum or raise a GitHub issue. We read everything and respond to most.

🚀 Installation

Getting started with Plane is simple. Choose the setup that works best for you:

  • Plane Cloud Sign up for a free account on Plane Cloud—it's the fastest way to get up and running without worrying about infrastructure.

  • Self-host Plane Prefer full control over your data and infrastructure? Install and run Plane on your own servers. Follow our detailed deployment guides to get started.

Installation methods Docs link
Docker Docker
Kubernetes Kubernetes

Instance admins can configure instance settings with God mode.

🌟 Features

  • Work Items Efficiently create and manage tasks with a robust rich text editor that supports file uploads. Enhance organization and tracking by adding sub-properties and referencing related issues.

  • Cycles Maintain your teams momentum with Cycles. Track progress effortlessly using burn-down charts and other insightful tools.

  • Modules Simplify complex projects by dividing them into smaller, manageable modules.

  • Views Customize your workflow by creating filters to display only the most relevant issues. Save and share these views with ease.

  • Pages Capture and organize ideas using Plane Pages, complete with AI capabilities and a rich text editor. Format text, insert images, add hyperlinks, or convert your notes into actionable items.

  • Analytics Access real-time insights across all your Plane data. Visualize trends, remove blockers, and keep your projects moving forward.

🛠️ Local development

See CONTRIBUTING

⚙️ Built with

React Router Django Node JS

📸 Screenshots

Plane Views

Plane Cycles and Modules

Plane Analytics

Plane Pages

📝 Documentation

Explore Plane's product documentation and developer documentation to learn about features, setup, and usage.

❤️ Community

Join the Plane community on GitHub Discussions and our Forum. We follow a Code of conduct in all our community channels.

Feel free to ask questions, report bugs, participate in discussions, share ideas, request features, or showcase your projects. Wed love to hear from you!

🛡️ Security

If you discover a security vulnerability in Plane, please report it responsibly instead of opening a public issue. We take all legitimate reports seriously and will investigate them promptly. See Security policy for more info.

To disclose any security issues, please email us at security@plane.so.

🤝 Contributing

There are many ways you can contribute to Plane:

Please read CONTRIBUTING.md for details on the process for submitting pull requests to us.

Repo activity

Plane Repo Activity

We couldn't have done this without you.

License

This project is licensed under the GNU Affero General Public License v3.0.