{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/plandex/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:plandex:plandex:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-85690"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Plandex (2.2.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","path-traversal","code-execution"],"_cs_type":"advisory","_cs_vendors":["Plandex"],"content_html":"\u003cp\u003ePlandex version 2.2.1 contains a critical path traversal vulnerability within its ApplyFiles function. This flaw arises from insufficient validation of file paths during the file application process, which is intended to update or create files within a designated project directory. An attacker who can influence the model's output, either through poisoned repository files or by supplying malicious context to the AI model, can force Plandex to write files to arbitrary locations on the host filesystem. By targeting sensitive directories, such as those containing shell initialization scripts (.bashrc, .zshrc) or cron job configurations, an attacker can achieve unauthorized code execution under the context of the user running the Plandex tool. This vulnerability represents a significant security risk for developers using Plandex in environments where the AI model's context might be influenced by untrusted sources.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies or creates a malicious repository file or manipulates the Plandex project context.\u003c/li\u003e\n\u003cli\u003eThe attacker triggers the Plandex model to generate a file update or creation action involving the ApplyFiles function.\u003c/li\u003e\n\u003cli\u003eThe model output is crafted to include path traversal sequences (e.g., ../../../) within the filename parameter.\u003c/li\u003e\n\u003cli\u003eThe ApplyFiles function fails to sanitize the provided path, allowing the write operation to escape the target project directory.\u003c/li\u003e\n\u003cli\u003eThe Plandex process performs an unauthorized write to a sensitive system or user location, such as ~/.bashrc.\u003c/li\u003e\n\u003cli\u003eThe target system or user triggers the malicious file (e.g., upon new shell login or cron execution).\u003c/li\u003e\n\u003cli\u003eArbitrary code defined by the attacker is executed on the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain remote code execution on the host machine running Plandex. This can lead to full system compromise, data exfiltration, or the establishment of persistent backdoors. Targeted environments include any developer workstation or server instance where Plandex is used to process code or configuration files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Plandex to a version addressing CVE-2026-85690 immediately once available from the vendor.\u003c/li\u003e\n\u003cli\u003eReview logs for unexpected file write operations originating from the Plandex process.\u003c/li\u003e\n\u003cli\u003eIsolate Plandex operations in a containerized or sandboxed environment with restricted filesystem access to mitigate the impact of path traversal.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T15:31:48Z","date_published":"2026-09-04T15:31:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-plandex-path-traversal/","summary":"Plandex version 2.2.1 contains a path traversal vulnerability in the ApplyFiles function allowing arbitrary file writes via manipulated model outputs, potentially leading to remote code execution.","title":"Path Traversal Vulnerability in Plandex","url":"https://feed.craftedsignal.io/briefs/2026-09-plandex-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Plandex","version":"https://jsonfeed.org/version/1.1"}