CVE-2026-19019: A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_
mediumvulnerabilityLLM-Specific
security
Summary
A security flaw was found in poco-ai poco-agent versions up to 0.5.4 in the WorkspaceManager._setup_session_persistence function, which results in incomplete cleanup (not fully removing temporary files or data after a session ends). The vulnerability is difficult to exploit and requires complex remote attacks, with a low severity rating (CVSS 2.9).
Vulnerability Details
CVSS Score
4.8(medium)
EPSS (30-day exploit probability)
EPSS: 0.3%
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Vector
network
Attack Complexity
high
Privileges Required
none
User Interaction
none
Disclosure Date
August 6, 2026
Classification
Attack SophisticationAdvanced
Impact (CIA+S)
integrityavailability
AI Component TargetedFramework
Taxonomy References
CWE (Weakness Type)
Affected Vendors
Monthly digest — independent AI security research
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19019
First tracked: August 6, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 75%