PatchSiren

poco-ai CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW poco-ai CVE published 2026-08-06

CVE-2026-19019

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T08:16:30.830Z and has not been modified since then. CVE-2026-19019 is a security flaw in poco-ai poco-agent up to version 0.5.4. The vulnerability affects the WorkspaceManager._setup_session_persistence function in executor/app/core/workspace.py, allowing remote attackers to perform complex attac [truncated]

MEDIUM poco-ai CVE published 2026-07-17

CVE-2026-16016

A server-side request forgery vulnerability was identified in poco-ai poco-claw up to 0.5.4. The issue affects the function run_task of the file executor/app/api/v1/task.py. The manipulation of the argument callback_url leads to server-side request forgery. The attack is possible to be carried out remotely. This vulnerability has a CVSS score of 5.5 and a MEDIUM severity.

LOW poco-ai CVE published 2026-07-17

CVE-2026-16015

CVE-2026-16015 is a vulnerability in poco-ai poco-claw up to 0.5.4, affecting the create_task function in executor_manager/app/api/v1/tasks.py. Exploitation may lead to missing authentication. Upgrading to version 0.5.7 or applying patch 67fcc88505c57f77d3fcf04eb5b89425b10cbf48 resolves the issue. This vulnerability has been publicly disclosed. Users should review official advisories and verify affected d [truncated]

MEDIUM poco-ai CVE published 2026-07-14

CVE-2026-15622

CVE-2026-15622 is an authorization bypass vulnerability in the Workspace API of Poco AI's Poco Claw up to version 0.5.4. The vulnerability is located in the get_workspace_file function within the executor_manager/app/api/v1/workspace.py file. An attacker can exploit this flaw by manipulating the user_id argument, potentially leading to unauthorized access. The vulnerability has been publicly disclosed and [truncated]