Vulnerability  ·  2026-10-11

Cohere Python SDK tar-slip in S3 model archive extraction → arbitrary file write on the host (CVSS 4.8)

VulnerabilityHigh impactGlobalCVE-2026-108597
Discovered via open-web sweep (not in the supplied seed): NVD REST API confirms publication 2026-10-10, CVSS 4.8, path traversal/tar-slip in the SDK's SageMaker model-dir download path. Requires the ability to place a crafted model archive in the victim's S3 prefix.
Model artifacts are an increasingly favored supply-chain vector into ML infrastructure — this turns a poisoned model archive in S3 into host file overwrite at extraction time on any machine using the Cohere SDK's SageMaker flows.
_s3_models_dir_to_tarfile extracts downloaded model archives with tarfile.extractall without validating member paths; absolute/../ members in a poisoned model archive perform arbitrary file write on the SDK host (CWE-22).
cohere-ai/cohere-python 5.11.0 through 7.2.0 (cohere_aws _s3_models_dir_to_tarfile; tarfile.extractall)
Upgrade past 7.2.0; validate tar member paths before extraction and only pull model archives from trusted prefixes. See VulnCheck advisory.
NVD CVE-2026-108597NVD REST APIVulnCheck advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →