Impact
Plandex 2.2.1 suffers from a path traversal flaw in its ApplyFiles command. The flaw allows an attacker to write files outside the intended project directory, including critical system files such as shell initialization scripts or cron job definitions. By placing malicious content in repository files or manipulating the context passed to the command, the attacker can cause the application to write code that runs with the service's privileges, leading to remote code execution.
Affected Systems
The affected product is Plandex version 2.2.1, developed by Plandex AI. No other versions are listed as vulnerable. Any deployment of that version is at risk, while earlier or later releases are not indicated as affected.
Risk and Exploitability
The CVSS score of 8.5 marks this as a high severity vulnerability. Epistemic probability of exploitation is unclear due to the lack of EPSS data, and the issue is not currently listed in CISA's KEV catalog. Nevertheless, the ability to overwrite system files gives an attacker the potential for code execution, which makes the risk significant especially in environments where the ApplyFiles functionality is exposed to untrusted input. Organizations running Plandex 2.2.1 should treat this flaw as a high priority security concern.
OpenCVE Enrichment