CVE-2026-55747: CWE-22 Path Traversal in The-Pocket PocketFlow (pocketflow-coding-agent cookbook example)
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Because os.path.join returns an absolute `p` unchanged (ignoring workdir) and does not resolve '../' sequences, an agent invocation whose file-tool arguments include an absolute path or a traversal sequence can read or write files outside the configured working directory. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.
AI Analysis
Technical Summary
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow uses a helper function _path(workdir, p) that wraps os.path.join(workdir, p) without performing canonicalization or containment checks. Since os.path.join returns an absolute path unchanged and does not resolve '../' sequences, an attacker can supply file-tool arguments with absolute paths or traversal sequences to read or write files outside the intended working directory. This vulnerability is classified as CWE-22 (Path Traversal). The severity is high due to potential unauthorized file access, but the impact is limited to applications that adopt this example code in production rather than the core PocketFlow library itself. No patch or official remediation is currently documented.
Potential Impact
This vulnerability allows an attacker to read or write files outside the configured working directory by exploiting the lack of path canonicalization and containment checks. This can lead to unauthorized disclosure or modification of files on the affected system. However, the impact is limited to applications that use the vulnerable cookbook example code in production environments, as the core PocketFlow library is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using the vulnerable cookbook example code in production or implement proper path canonicalization and containment checks to prevent path traversal. Specifically, ensure that file paths are resolved and validated to remain within the intended working directory before performing file operations.
CVE-2026-55747: CWE-22 Path Traversal in The-Pocket PocketFlow (pocketflow-coding-agent cookbook example)
Description
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a `_path(workdir, p)` helper as a thin os.path.join(workdir, p) wrapper with no canonicalization or containment check, used unguarded by the ReadFile, ListFiles, PatchRead, and PatchApply file-access tools. Because os.path.join returns an absolute `p` unchanged (ignoring workdir) and does not resolve '../' sequences, an agent invocation whose file-tool arguments include an absolute path or a traversal sequence can read or write files outside the configured working directory. Severity reflects that this affects an illustrative cookbook example rather than a core library API; applications that copy this pattern into production are affected.
CVSS v3.1
Score 6.8medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow uses a helper function _path(workdir, p) that wraps os.path.join(workdir, p) without performing canonicalization or containment checks. Since os.path.join returns an absolute path unchanged and does not resolve '../' sequences, an attacker can supply file-tool arguments with absolute paths or traversal sequences to read or write files outside the intended working directory. This vulnerability is classified as CWE-22 (Path Traversal). The severity is high due to potential unauthorized file access, but the impact is limited to applications that adopt this example code in production rather than the core PocketFlow library itself. No patch or official remediation is currently documented.
Potential Impact
This vulnerability allows an attacker to read or write files outside the configured working directory by exploiting the lack of path canonicalization and containment checks. This can lead to unauthorized disclosure or modification of files on the affected system. However, the impact is limited to applications that use the vulnerable cookbook example code in production environments, as the core PocketFlow library is not affected.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should avoid using the vulnerable cookbook example code in production or implement proper path canonicalization and containment checks to prevent path traversal. Specifically, ensure that file paths are resolved and validated to remain within the intended working directory before performing file operations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-06-17T12:59:17.621Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a72e5c6bf8831d539734f55
Added to database: 08/05/2026, 07:27:02 UTC
Last enriched: 08/05/2026, 07:56:16 UTC
Last updated: 08/06/2026, 00:41:14 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.