Impact
The pocketflow-coding-agent cookbook example implements a helper that combines a working directory with a supplied path without canonicalization or containment checks. When the ReadFile, ListFiles, PatchRead, or PatchApply tools invoke this helper, an attacker can provide an absolute path or a sequence that traverses directories. This allows the agent to read or write files outside its intended working directory, effectively leaking or modifying arbitrary files.
Affected Systems
The vulnerable code resides in The‑Pocket’s PocketFlow, specifically the pocketflow‑coding‑agent cookbook example. No exact version information is supplied, so any deployment that includes this example and has the file‑tool helpers exposed is potentially affected.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1 and is not listed in CISA’s KEV catalog. Because the bug permits file access through untrusted input to a helper used by several file‑tool commands, an attacker who can supply arguments to the agent—either through a local interface or an exposed API—can exploit the flaw. The lack of an EPSS score means the current public data does not indicate widespread exploitation, but the high severity suggests that exposure should be addressed promptly.
OpenCVE Enrichment