{"data":{"id":"8851b2da-3309-40fa-824c-a7238d9ce654","title":"CVE-2025-61163: Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This","summary":"Cohere North AI v1.1.5 has a security flaw where the server accepts connections from any website without properly checking where the request comes from, because it fails to validate the Origin header (a piece of information that identifies which domain a web request originated from). This could allow attackers from untrusted websites to interact with the AI system in unintended ways.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-61163","publishedAt":"2026-08-26T19:16:44.290Z","cveId":"CVE-2025-61163","cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":["Cohere"],"affectedVendorsRaw":["Cohere North AI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-08-26T19:16:44.290Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":null}}