Path Traversal Vulnerability in Cohere Python SDK by Cohere AI
CVE-2026-108597
5.9MEDIUM
What is CVE-2026-108597?
The Cohere Python SDK versions 5.11.0 through 7.2.0 are susceptible to a path traversal vulnerability that arises in the _s3_models_dir_to_tarfile method. This vulnerability enables attackers to exploit the unvalidated tarfile.extractall calls within the SDK to overwrite files on the host system. If an attacker can write model archives to a victim's S3 prefix, they can leverage absolute paths or '../' sequences to gain unauthorized access to system files. This issue necessitates caution for users leveraging the Cohere Python SDK for operations involving S3 storage.
Affected Version(s)
cohere-python 5.11.0 <= 7.2.0
References
CVSS V4
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
HaiND from the Post and Telecommunication Institute of Technology
