An arbitrary file upload vulnerability in the /v1/mydrive/batchupload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.
Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USERID}} endpoint
Cohere North AI v1.1.5 was discovered to contain an information leak via the WebSocket Endpoint.