Sceawere
Vulnerability Detail
CVE-2026-108597UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cohere SDK Tar Slip Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.8
- Creation Date
- 3h ago
- Vendor
- cohere-ai
- Product
- cohere-python
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Cohere Python SDK 5.11.0 through 7.2.0 contains a path traversal (tar slip) vulnerability in _s3_models_dir_to_tarfile that allows arbitrary file write via unvalidated tarfile.extractall calls. Attackers who can write model archives to the victim's S3 prefix can include absolute paths or ../ members to overwrite files on the SDK host.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.8",
"pubDate": "2026-10-10T19:16:58.210Z",
"pubdate": "2026-10-10T19:16:58.210Z",
"executiveSummary": "The Cohere Python SDK, specifically versions 5.11.0 through 7.2.0, is susceptible to a path traversal vulnerability commonly referred to as a 'Tar Slip'.\nThe vulnerability originates in the _s3_models_dir_to_tarfile function, which improperly processes tar archives downloaded from external sources, specifically S3 prefixes.\nBy leveraging unvalidated tarfile.extractall calls, an attacker with the ability to write or modify model archives within the victim's S3 bucket can craft malicious file paths.\nThese paths can contain absolute directory traversals (e.g., '../') or absolute system paths, enabling the arbitrary overwrite of files on the underlying SDK host filesystem.\nThis represents a significant security risk, as successful exploitation could lead to Remote Code Execution (RCE), unauthorized configuration modification, or the corruption of critical system binaries, depending on the permissions of the process running the SDK.\nThe attack is contingent upon the adversary's capability to influence the content of the S3-hosted archives, making it a critical threat for environments utilizing untrusted or inadequately secured S3 storage buckets for model distribution.",
"technicalDetails": "The vulnerability is situated within the _s3_models_dir_to_tarfile utility function, which is responsible for handling the extraction of model files retrieved from S3 storage.\nThe root cause of this flaw is the insecure implementation of the Python tarfile.extractall method. This method, by default, does not validate the integrity or the target destination of members contained within a tar archive.\nAn attacker can craft a malicious tar archive where filenames are prefixed with '..' sequence or absolute file paths. When the SDK calls extractall, it blindly follows these paths, causing the filesystem to write the extracted content outside of the intended extraction directory.\nThe attack flow begins when an attacker gains write access to the specific S3 prefix monitored or consumed by the Cohere SDK. The attacker uploads a weaponized tar file containing files with malicious, traversable metadata names.\nWhen the Cohere Python SDK executes the _s3_models_dir_to_tarfile routine, the underlying call to extractall traverses the directory structure of the host machine.\nIf the SDK process runs with elevated privileges or has write access to sensitive directories, the attacker can overwrite critical files such as shell configuration scripts (e.g., .bashrc, .profile), system binaries, or application configuration files.\nThis exploitation technique effectively bypasses sandbox or directory constraints, allowing the attacker to escape the application's workspace.\nThe impact of this vulnerability is severe; because the SDK facilitates the automated handling of model files, an adversary can achieve arbitrary code execution by replacing legitimate libraries or scripts with malicious payloads that are subsequently executed by the application or the host environment.\nThe vulnerability affects all versions of the Cohere Python SDK from 5.11.0 up to and including 7.2.0. No authentication is required within the SDK itself, as the primary constraint is the attacker's ability to influence the external S3 bucket content.\nThe exploitation does not require direct network exposure of the target machine itself, but rather relies on the integrity of the S3 storage mechanism, which is treated as a trusted source by the vulnerable function."
}