What happened
Discovered via open-web sweep (not in the supplied seed): NVD REST API confirms publication 2026-10-10, CVSS 4.8, path traversal/tar-slip in the SDK's SageMaker model-dir download path. Requires the ability to place a crafted model archive in the victim's S3 prefix.
Why it matters
Model artifacts are an increasingly favored supply-chain vector into ML infrastructure — this turns a poisoned model archive in S3 into host file overwrite at extraction time on any machine using the Cohere SDK's SageMaker flows.
Attack vector
_s3_models_dir_to_tarfile extracts downloaded model archives with tarfile.extractall without validating member paths; absolute/../ members in a poisoned model archive perform arbitrary file write on the SDK host (CWE-22).
Affected systems
cohere-ai/cohere-python 5.11.0 through 7.2.0 (cohere_aws _s3_models_dir_to_tarfile; tarfile.extractall)
Mitigation
Upgrade past 7.2.0; validate tar member paths before extraction and only pull model archives from trusted prefixes. See VulnCheck advisory.