Impact
Cohere North AI v1.1.5 contains an overly permissive cross-domain policy that does not validate the Origin header of incoming requests. The flaw appears to allow an external domain to send requests with a forged Origin header, effectively bypassing server access controls. Based on the description, it is inferred that this could allow attackers to perform actions on behalf of the server or exfiltrate data, depending on the server’s exposed endpoints. This improper access control is a CWE‑942 and CWE‑346 weakness.
Affected Systems
Cohere North AI, version 1.1.5, is the only product mentioned. No other vendors or versions are indicated.
Risk and Exploitability
Based on the description, the likely attack vector is a remote host forging an HTTP request with a malformed or fabricated Origin header. The CVSS score is 9.8 and EPSS < 1%; it is not listed in CISA’s KEV catalog, but the misconfiguration is exploitable by any remote host capable of forging such a request. Given the lack of protection in the default configuration, the risk is significant for services exposed to the Internet; the low EPSS indicates that exploitation is not yet widespread, but the high severity remains.
OpenCVE Enrichment