CyberRota Analysis
AI-GeneratedPlandex 2.2.1 is vulnerable to a path traversal flaw in the ApplyFiles function, enabling attackers to write files outside the intended project directory. This vulnerability can be exploited to manipulate model outputs by injecting malicious files into critical system locations, potentially leading to arbitrary code execution. Organizations using this software should prioritize remediation to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model output through poisoned repository files or attacker-controlled context to write to arbitrary locations like shell rc or cron files, achieving code execution.