CVE-2026-108597: Cohere-Ai Cohere-Python
Medium severity, CVSS 4.8.
Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.
Affected products
- Cohere-Ai Cohere-Python: from 5.11.0, up to and including 7.2.0
Published 2026-10-10. Last modified 2026-10-10.