c
cohere
Security Risk Profile
86
/100
criticalSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 12, 2024 to present
4
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
9.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
86/100
critical
📈 2 in Last 30 Days
Severity Distribution
Critical
2High
0Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Malicious File Upload
1
Most Affected Products
1. Cohere North AI2
2. Cohere Terrarium1
3. OpenAI Codex CLI1
4. Google API and Google Cloud keys1
5. OpenWeatherMap bot tokens1
Recent Vulnerabilities
See more →CVE-2025-61165
CVSS 9.8critical
Aug 26, 2026🔧 No Patch
CVE-2025-61163
CVSS 9.8critical
Aug 26, 2026🔧 No Patch
https://reddit.com/r/netsec/comments/1suh47t/cohere_terrarium_cve20265752_and_openai_codex_cli/
unknown
Cohere Terrarium (CVE-2026-5752) and OpenAI Codex CLI (CVE-2025-59532): a cross-CVE analysis of AI code sandbox escapes
Apr 24, 2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/
unknown
Over 12 million auth secrets and keys leaked on GitHub in 2023
Mar 12, 2024🔧 No Patch
Monitor cohere in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.