CVE-2025-61163: Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This
Summary
Cohere North AI v1.1.5 has a security flaw where the server accepts connections from any website without properly checking where the request comes from, because it fails to validate the Origin header (a piece of information that identifies which domain a web request originated from). This could allow attackers from untrusted websites to interact with the AI system in unintended ways.
Vulnerability Details
EPSS: 0.0%
August 26, 2026
Classification
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-61163
First tracked: August 26, 2026 at 08:08 PM
Classified by LLM (prompt v3) · confidence: 85%