Impact
An attacker can upload a specially crafted file to the /v1/my_drive/batch_upload endpoint of Cohere North AI version 1.1.5, causing arbitrary code to run on the host. This flaw stems from insufficient validation of uploaded content, which the description explicitly identifies as a CWE‑434 weakness. The resulting compromise threatens confidentiality, integrity, and availability by potentially granting the attacker full control of the affected system.
Affected Systems
Cohere North AI version 1.1.5 is the only product noted to contain this vulnerability. The flaw resides in the batch upload component handling user files; all installations of this release that expose the /v1/my_drive/batch_upload endpoint are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies this as a critical vulnerability, and the EPSS score of < 1% indicates a low overall exploitation probability, although the vulnerability is listed as not in the CISA KEV catalog. Nevertheless, the remote nature of the vulnerability and the lack of required privilege escalation steps imply a high risk for any system that accepts uploads through this endpoint. The likely attack path is remote, requiring an attacker to submit a malicious file via the exposed API; execution then occurs with the privileges of the service process.
OpenCVE Enrichment