MediumVulnerability
CVE-2026-108597: Cohere Python SDK path traversal in model archive extraction
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-108597
- Published
- Record updated
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
Summary
Cohere Python SDK versions 5.11.0 through 7.2.0 contain a path traversal (tar slip) flaw in _s3_models_dir_to_tarfile. Its unvalidated tarfile.extractall calls allow arbitrary file writes. An attacker who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Related items
- HighCVE-2025-61165: Cohere North AI arbitrary file upload via /v1/my_drive/batch_uploadSame vendor · NVD/CVE Database
- MediumCVE-2025-61164: Cohere North AI information leak via the WebSocket endpointSame vendor · NVD/CVE Database
- MediumCVE-2025-61163: Cohere North AI excessively permissive cross-domain policy via Origin headerSame vendor · NVD/CVE Database
- HighCVE-2025-61162: Cohere North AI access control flaw allows overwriting user infoSame vendor · NVD/CVE Database
- MediumCVE-2026-108670: JeecgBoot missing authorization in AiragPromptsControllerSimilar attack · NVD/CVE Database