Vendor
Plandex version 2.2.1 contains a path traversal vulnerability in the ApplyFiles function allowing arbitrary file writes via manipulated model outputs, potentially leading to remote code execution.