Impact
Cohere North AI v1.1.5 contains an information leak through its WebSocket endpoint, allowing attackers to read data that should be protected. The vulnerability can expose sensitive data transmitted via WebSocket connections.
Affected Systems
Cohere North AI v1.1.5 is the only affected product, with no other versions enumerated in the advisory.
Risk and Exploitability
The exploitability details are limited; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, implying low to moderate exploitation probability. Attackers would need remote network connectivity to reach the WebSocket endpoint, so protecting this endpoint at the network layer and ensuring only authorized users can access it will mitigate risk.
OpenCVE Enrichment