CVE-2026-19019

Source
https://cve.org/CVERecord?id=CVE-2026-19019
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19019.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19019
Published
2026-08-06T07:30:10.590Z
Modified
2026-08-14T03:51:45.858022990Z
Severity
  • 2.9 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
Details

A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager.setupsession_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/19xxx/CVE-2026-19019.json",
    "cwe_ids": [
        "CWE-459"
    ]
}
References

Affected packages

Git / github.com/poco-ai/poco-claw

Affected ranges

Type
GIT
Repo
https://github.com/poco-ai/poco-claw
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "0.5.0"
        },
        {
            "last_affected": "0.5.0"
        },
        {
            "introduced": "0.5.1"
        },
        {
            "last_affected": "0.5.1"
        },
        {
            "introduced": "0.5.2"
        },
        {
            "last_affected": "0.5.2"
        },
        {
            "introduced": "0.5.3"
        },
        {
            "last_affected": "0.5.3"
        },
        {
            "introduced": "0.5.4"
        },
        {
            "last_affected": "0.5.4"
        }
    ]
}

Affected versions

0.*
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
v0.*
v0.5.0
v0.5.1
v0.5.2
v0.5.3
v0.5.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19019.json"