aisecwatch.com
DashboardVulnerabilitiesNewsResearchArchiveStatsDatasetFor devs
Subscribe
aisecwatch.com

Real-time AI security monitoring. Tracking AI-related vulnerabilities, safety and security incidents, privacy risks, research developments, and policy changes.

Navigation

VulnerabilitiesNewsResearchDigest ArchiveNewsletter ArchiveSubscribeData SourcesStatisticsDatasetAPIIntegrationsWidgetRSS Feed

Maintained by

Truong (Jack) Luu

Information Systems Researcher

AI & LLM Vulnerabilities

Security vulnerabilities, privacy incidents, safety concerns, and policy updates affecting LLMs and AI agents.

to
Export CSV
4 items

CVE-2025-61165: An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac

criticalvulnerability
security
Aug 26, 2026
CVE-2025-61165

Cohere North AI version 1.1.5 has a vulnerability in its file upload feature (/v1/my_drive/batch_upload) that lets attackers upload specially crafted files to run arbitrary code (commands they choose) on the system. This is a serious security flaw because it gives attackers direct control over the affected computer.

NVD/CVE Database

CVE-2025-61164: Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.

highvulnerability
security
Aug 26, 2026
CVE-2025-61164

Cohere North AI version 1.1.5 has a security flaw where sensitive information can leak through its WebSocket endpoint (a two-way communication channel between a client and server). This vulnerability allows unauthorized access to data that should be protected.

CVE-2025-61163: Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This

highvulnerability
security
Aug 26, 2026
CVE-2025-61163

Cohere North AI v1.1.5 has a security flaw where the server accepts connections from any website without properly checking where the request comes from, because it fails to validate the Origin header (a piece of information that identifies which domain a web request originated from). This could allow attackers from untrusted websites to interact with the AI system in unintended ways.

CVE-2025-61162: Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted req

highvulnerability
security
Aug 26, 2026
CVE-2025-61162

Cohere North AI version 1.1.5 has a flaw in its access control (the system that checks whether a user is allowed to perform an action) that lets attackers modify other users' information by sending specially crafted requests to a specific API endpoint. This means an attacker could change someone else's user data without permission.

NVD/CVE Database
NVD/CVE Database
NVD/CVE Database