CVE-2026-39843 | makeplane up to 1.2.x fetch_and_encode_favicon server-side request forgery
A vulnerability has been found in makeplane plane up to 1.2.x and classified as critical. This affects the function fetch_and_encode_favicon. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2026-39843. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.