Vendor
Cohere
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-61165 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file. | ||
| CVE-2025-61163 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests. | ||
| CVE-2025-61164 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint. | ||
| CVE-2025-61162 | Hig | 0.49 | 7.5 | 0.00 | Aug 26, 2026 | Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint |
- risk 0.64cvss 9.8epss 0.00
An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.00
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
- risk 0.49cvss 7.5epss 0.00
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
- risk 0.49cvss 7.5epss 0.00
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint