Description
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
Published: 2026-08-26
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch/Restrict
AI Analysis

Impact

Cohere North AI v1.1.5 contains an information leak through its WebSocket endpoint, allowing an attacker to read data that should be protected. The vulnerability enables the exposure of sensitive data transmitted via WebSocket connections. This weakness is identified as a CWE-200 and CWE-319 information disclosure flaw.

Affected Systems

Cohere North AI v1.1.5 is the only affected product; no other versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk, while the EPSS score of less than 1% suggests a low to moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would require remote network connectivity to reach the WebSocket endpoint, so the likely attack vector is inferred to be remote over the network. Protecting this endpoint at the network layer and ensuring only authorized users can access it will mitigate risk.

Generated by OpenCVE AI on September 1, 2026 at 13:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor remediation fix or upgrade to a patched release of Cohere North AI if one is available.
  • Restrict network access to the WebSocket endpoint using firewall rules or network segmentation in accordance with CWE-200 mitigations.
  • Disable or block the vulnerable WebSocket endpoint if it is not required for operations.
  • Monitor authentication logs for unauthorized WebSocket access and consider implementing additional access controls.

Generated by OpenCVE AI on September 1, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Cohere North AI: Cohere North AI: Information Leak via WebSocket Endpoint
Weaknesses CWE-319
References
Metrics threat_severity

None

threat_severity

Important


Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Information Leak via WebSocket Endpoint in Cohere North AI v1.1.5

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 26 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Information Leak via WebSocket Endpoint in Cohere North AI v1.1.5
Weaknesses CWE-200

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:14:14.634Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61164

cve-icon Vulnrichment

Updated: 2026-08-27T19:14:05.617Z

cve-icon NVD

Status : Deferred

Published: 2026-08-26T19:16:44.797

Modified: 2026-09-03T17:45:20.840

Link: CVE-2025-61164

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-26T00:00:00Z

Links: CVE-2025-61164 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:00:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-319

    Cleartext Transmission of Sensitive Information