CVE-2026-19019: poco-ai poco-agent Claude File workspace.py WorkspaceManager._setup_session_persistence cleanup
A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager.setupsessionpersistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19019?
The severity of CVE-2026-19019 is medium with a score of 4.8.
What software is affected by CVE-2026-19019?
CVE-2026-19019 affects poco-ai poco-agent versions up to 0.5.4.
How do I fix CVE-2026-19019?
To fix CVE-2026-19019, update your poco-ai poco-agent to a version that addresses this vulnerability.
What is the impact of CVE-2026-19019?
The impact of CVE-2026-19019 is incomplete cleanup within the WorkspaceManager._setup_session_persistence function.
Can CVE-2026-19019 be exploited remotely?
Yes, CVE-2026-19019 can be exploited remotely due to its access vector being classified as AV:N.