AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T19:16:44.927Z and has not been modified since then. CVE-2025-61165 is a critical vulnerability in Cohere North AI v1.1.5, allowing attackers to execute arbitrary code via a crafted file upload in the /v1/my_drive/batch_upload component. The vulnerability has a CVSS score of 9.8 and is considered [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T19:16:44.290Z and has not been modified since then. Cohere North AI v1.1.5 contains an excessively permissive cross-domain policy vulnerability due to the server's failure to validate the Origin header of incoming connection requests. This vulnerability could potentially allow unauthorized access [truncated]
CVE-2026-5752 is a critical vulnerability in Terrarium that allows arbitrary code execution with root privileges via JavaScript prototype chain traversal. The vulnerability has a CVSS score of 9.3 and is classified as CRITICAL. This issue arises from a sandbox escape, enabling attackers to execute code with elevated privileges. Users of Terrarium should be aware of this vulnerability and take immediate ac [truncated]