PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108597 cohere-ai CVE debrief

The Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host. This vulnerability can be exploited by attackers who have the ability to write model archives to the victim's S3 prefix, potentially leading to arbitrary file writes on the SDK host.

Vendor
cohere-ai
Product
cohere-python
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-10
Original CVE updated
2026-10-10
Advisory published
2026-10-10
Advisory updated
2026-10-10

Who should care

Defenders who use the Cohere Python SDK should assess exposure and prioritize verification and mitigation. This includes reviewing the affected versions of the SDK, applying patches or mitigations, and monitoring for suspicious activity. Additionally, defenders should consider compensating controls for exposed systems and review relevant monitoring, detection, and logs for exposed assets.

Why it matters

The Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability that allows arbitrary file write via unvalidated tarfile.extractall calls. Defenders who use the Cohere Python SDK should assess exposure and prioritize verification and mitigation.

  • Verify affected versions of the Cohere Python SDK
  • Apply patches or mitigations to prevent exploitation
  • Monitor for suspicious activity related to the Cohere Python SDK

Technical summary

The Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. This vulnerability can be exploited by attackers who have the ability to write model archives to the victim's S3 prefix, potentially leading to arbitrary file writes on the SDK host. The issue arises from the lack of validation in the tarfile.extractall calls, enabling attackers to include absolute paths or ../ members in the model archives.

Defensive priority

Defenders should prioritize verifying the affected versions of the Cohere Python SDK and applying patches or mitigations to prevent exploitation.

Recommended defensive actions

  • Verify the affected versions of the Cohere Python SDK
  • Apply patches or mitigations to prevent exploitation
  • Monitor for suspicious activity related to the Cohere Python SDK
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability is caused by a path traversal issue in the _s3_models_dir_to_tarfile function, which allows attackers to write arbitrary files on the SDK host. The issue arises from the lack of validation in the tarfile.extractall calls, enabling attackers to include absolute paths or ../ members in the model archives. This could lead to the overwriting of files on the SDK host. Evidence of this vulnerability is based on the source-provided information and the CVE record.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108597 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108597

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108597 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108597

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.