CVE-2026-55747

MEDIUM

PocketFlow: Path Traversal in pocketflow-coding-agent Cookbook Example File Tools

Title source: cna
STIX 2.1

Description

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.

References (1)

Core 1
Core References

Scores

CVSS v3 6.8
EPSS 0.0026
EPSS Percentile 17.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
The-Pocket/PocketFlow (pocketflow-coding-agent cookbook example)
Published Aug 05, 2026
Tracked Since Aug 05, 2026