Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-26 19:16
Updated : 2026-09-03 17:45
NVD link : CVE-2025-61163
Mitre link : CVE-2025-61163
CVE.ORG link : CVE-2025-61163
JSON object : View
Products Affected
No product.
CWE
CWE-942
Permissive Cross-domain Security Policy with Untrusted Domains
