CVE-2026-55747
MEDIUMPocketFlow: Path Traversal in pocketflow-coding-agent Cookbook Example File Tools
Title source: cnaDescription
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.
References (1)
Core 1
Core References
third-party-advisory
https://github.com/The-Pocket/PocketFlow
Scores
CVSS v3
6.8
EPSS
0.0026
EPSS Percentile
17.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-22
Status
published
Products (1)
The-Pocket/PocketFlow (pocketflow-coding-agent cookbook example)
Published
Aug 05, 2026
Tracked Since
Aug 05, 2026