CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108597

MEDIUMCVSS 4.8NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-108597 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-108597

MEDIUMCVSS 4.8NVD feed

Published 10 October 2026 · tracked since 11 October 2026

Description

Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]