← Terug naar overzicht

Plandex version 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the intended project directory. The flaw can be exploited by influencing AI model output through poisoned repository files or attacker-controlled context inputs. Successful exploitation enables writing to arbitrary locations such as shell rc files or cron job configurations. This can lead to arbitrary code execution on the affected system. The vulnerability is tracked as CVE-2026-85690 and has been documented by VulnCheck. The affected code resides in app/cli/lib/apply.go within the Plandex CLI. The issue has been reported via GitHub and is publicly disclosed. Users of Plandex 2.2.1 are advised to review available patches or mitigations immediately.

Affected products

  • Plandex 2.2.1

Related CVE's

  • CVE-2026-85690

Categories

  • Emerging Technologies
  • Supply Chain & Dependencies
  • Web Technologies
  • Zero-Day Vulnerabilities