Executive brief
Cohere North is an enterprise AI platform that processes and manages data for business intelligence and automation. A flaw in the file upload component allows attackers to upload malicious files that execute arbitrary code on the platform, potentially compromising sensitive business data, disrupting AI-powered operations, and establishing a foothold for further attacks.
Technical details
This is an arbitrary file upload vulnerability in the /v1/my_drive/batch_upload API endpoint of Cohere North v1.1.5. The vulnerability allows an attacker to upload a crafted file (likely a script or executable) that bypasses file type validation, leading to remote code execution on the server. The attack is network-accessible and does not appear to require authentication based on the endpoint naming convention. Once exploited, an attacker gains the ability to execute arbitrary code with the privileges of the application, potentially leading to data exfiltration, lateral movement, or complete platform compromise. A patch is expected to be available in the near future.
Affected products
- Cohere North 1.1.5
Timeline
- 2026-08-26: disclosed