CVE-2025-61163: Cohere North AI vulnerability
Published Aug 26, 2026
·Updated
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
Affected Software
1 affected component
Cohere North AI=1.1.5
Event History
Aug 26, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:16 PM
Description
Frequently Asked Questions
1
What deployments are known to be affected?
Cohere North AI version 1.1.5 is identified as affected. The issue is in the server's handling of incoming connection requests.
2
What must an attacker do to exploit this issue?
An attacker would need to send a connection request with an Origin header from an untrusted domain. The server fails to validate that Origin header, allowing an excessively permissive cross-domain policy.