Impact
Cohere North AI v1.1.5 contains an information leak through its WebSocket endpoint, allowing an attacker to read data that should be protected. The vulnerability enables the exposure of sensitive data transmitted via WebSocket connections. This weakness is identified as a CWE-200 and CWE-319 information disclosure flaw.
Affected Systems
Cohere North AI v1.1.5 is the only affected product; no other versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 7.5 indicates a high risk, while the EPSS score of less than 1% suggests a low to moderate likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would require remote network connectivity to reach the WebSocket endpoint, so the likely attack vector is inferred to be remote over the network. Protecting this endpoint at the network layer and ensuring only authorized users can access it will mitigate risk.
OpenCVE Enrichment