PT-2026-109738 · Cohere Ai · Cohere-Python

·

CVE-2026-108597

·

Publicado

2026-10-10

·

Atualizado

2026-10-10

CVSS v3.1

4.8

Média

VetorAV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in s3 models dir to tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-108597

Produtos afetados

Cohere-Python