Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.
Cohere North AI version 1.1.5 has a vulnerability in its file upload feature (/v1/my_drive/batch_upload) that lets attackers upload specially crafted files to run arbitrary code (commands they choose) on the system. This is a serious security flaw because it gives attackers direct control over the affected computer.
Cohere North AI version 1.1.5 has a security flaw where sensitive information can leak through its WebSocket endpoint (a two-way communication channel between a client and server). This vulnerability allows unauthorized access to data that should be protected.
Cohere North AI v1.1.5 has a security flaw where the server accepts connections from any website without properly checking where the request comes from, because it fails to validate the Origin header (a piece of information that identifies which domain a web request originated from). This could allow attackers from untrusted websites to interact with the AI system in unintended ways.
Cohere North AI version 1.1.5 has a flaw in its access control (the system that checks whether a user is allowed to perform an action) that lets attackers modify other users' information by sending specially crafted requests to a specific API endpoint. This means an attacker could change someone else's user data without permission.