CVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attackers to exeute arbitrary code via uploading a crafted file.

  • Published Aug 26, 2026
  • CVSS 9.8 critical
  • 0.4% chance of exploitation in the next 30 days (EPSS)

CVE-2025-61165 at the National Vulnerability Database