GHSA-rg44-2cq2-qx25MediumCVSS 4.8

Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in...

Published
October 10, 2026
Last Modified
October 10, 2026

🔗 CVE IDs covered (1)

📋 Description

Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.

🔗 References (6)