CVE-2026-85690 Details
Description
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary locations like shell rc or cron files, achieving code execution.
A path traversal vulnerability has been identified in Plandex version 2.2.1, specifically within the ApplyFiles function. This vulnerability allows attackers to write files outside the designated project directory. Exploitation can occur by manipulating model output through poisoned repository files or attacker-controlled context, directing writes to arbitrary locations such as shell rc or cron files, which could lead to code execution.
Update to Plandex version 2.2.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/plandex-ai/plandex | [email protected] | Vendor |
| https://github.com/plandex-ai/plandex/blob/cli/v2.2.1/app/cli/lib/apply.go | [email protected] | Source CodeVendor |
| https://github.com/plandex-ai/plandex/issues/352 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://www.vulncheck.com/advisories/plandex-2.2.1-path-traversal-via-applyfiles | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Plandex | <= 2.2.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion