A vulnerability was found in poco-ai poco-agent up to 0.5.4 and classified as problematic. Affected is the function
WorkspaceManager._setup_session_persistence of the file executor/app/core/workspace.py of the component Claude File Handler. The manipulation results in incomplete cleanup.
This vulnerability was named CVE-2026-19019. The attack may be performed from remote. In addition, an exploit is available.