CVE-2026-85690: Plandex 2.2.1 Path Traversal via ApplyFiles

Published Sep 4, 2026
·
Updated

Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary locations like shell rc or cron files, achieving code execution.

Affected Software

1 affected component
Plandex=2.2.1

Event History

Sep 4, 2026
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What conditions are required for exploitation?

An attacker must be able to influence the model output, such as through poisoned files in a repository or attacker-controlled context. Exploitation also requires a user to interact with the affected workflow, as reflected by the user-interaction requirement.

2

What is the practical impact of a successful exploit?

The attacker can cause files to be written outside the intended project directory. Writing to locations such as shell startup files or cron files can lead to code execution.

3

How can teams identify whether they are affected?

Teams using Plandex 2.2.1 should review workflows that use ApplyFiles, particularly where repositories or context may contain attacker-controlled content. The issue is specifically associated with path handling in the ApplyFiles function.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203