GHSA-6pmx-p277-96g6HighCVSS 7.5

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user...

Published
August 26, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Incorrect access control in Cohere North AI v1.1.5 allows attackers to arbitrarily overwrite user info via a crafted request to the /api/internal/v1/users/{{USER_ID}} endpoint

🔗 References (4)