Impact
An attacker can upload a specially crafted file to the /v1/my_drive/batch_upload endpoint of Cohere North AI version 1.1.5, causing arbitrary code to run on the host. This flaw stems from insufficient validation of uploaded content, which the description explicitly identifies as a CWE‑434 weakness. The resulting compromise threatens confidentiality, integrity, and availability by potentially granting the attacker full control of the affected system.
Affected Systems
Cohere North AI version 1.1.5 is the only product noted to contain this vulnerability. The flaw resides in the batch upload component handling user files; all installations of this release that expose the /v1/my_drive/batch_upload endpoint are considered vulnerable.
Risk and Exploitability
Because no CVSS score or EPSS value is publicly available and the issue is not listed in the CISA KEV catalog, precise exploitation probability cannot be quantified. Nevertheless, the remote nature of the vulnerability and the lack of required privilege escalation steps imply a high risk for any system that accepts uploads through this endpoint. The likely attack path is remote, requiring an attacker to submit a malicious file via the exposed API; execution then occurs with the privileges of the service process.
OpenCVE Enrichment