Vendor
Atlantis versions 0.19.8 through 0.44.9 are vulnerable to path traversal (CVE-2026-64679) allowing unauthorized directory creation or deletion outside the intended workspace root.