Path Traversal Vulnerability in Cohere Python SDK by Cohere AI
CVE-2026-108597

5.9MEDIUM

Key Information:

Vendor

Cohere-ai

Vendor
CVE Published:
10 October 2026

What is CVE-2026-108597?

The Cohere Python SDK versions 5.11.0 through 7.2.0 are susceptible to a path traversal vulnerability that arises in the _s3_models_dir_to_tarfile method. This vulnerability enables attackers to exploit the unvalidated tarfile.extractall calls within the SDK to overwrite files on the host system. If an attacker can write model archives to a victim's S3 prefix, they can leverage absolute paths or '../' sequences to gain unauthorized access to system files. This issue necessitates caution for users leveraging the Cohere Python SDK for operations involving S3 storage.

Affected Version(s)

cohere-python 5.11.0 <= 7.2.0

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

HaiND from the Post and Telecommunication Institute of Technology
.