CVE-2025-61163

Published: Ago 26, 2026 Last Modified: Ago 26, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This occurs via the server failing to validate the Origin header of incoming connection requests.

https://cohere.com/north
https://github.com/bdadoa/Cohere---North-AI-1.1.5---Vulnerabilities/blob/main/C…