Description
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
Published: 2026-08-26
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Excessively Permissive CORS Policy in Cohere North AI v1.1.5 Cohere North AI: Cohere North AI: Information disclosure via improper Origin header validation
Weaknesses CWE-346
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 28 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Excessively Permissive CORS Policy in Cohere North AI v1.1.5

Fri, 28 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 28 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Title Cohere North AI v1.1.5 CORS Misconfiguration Exposes Server to Untrusted Origins
Weaknesses CWE-284

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-942
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cohere North AI v1.1.5 CORS Misconfiguration Exposes Server to Untrusted Origins
Weaknesses CWE-284

Wed, 26 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Description Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T19:16:12.423Z

Reserved: 2025-09-26T00:00:00.000Z

Link: CVE-2025-61163

cve-icon Vulnrichment

Updated: 2026-08-27T19:16:04.529Z

cve-icon NVD

Status : Received

Published: 2026-08-26T19:16:44.290

Modified: 2026-08-27T20:17:00.617

Link: CVE-2025-61163

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-26T00:00:00Z

Links: CVE-2025-61163 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T18:00:18Z

Weaknesses