ChromaGHSA-36p7-vc44-83pf
ChromaDB has a code injection vulnerability
CriticalCVE-2026-45833 · Published Jun 12, 2026 · updated Sep 10, 2026
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| chromadb PyPI | >= 0.4.17, <= 1.5.9 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2026-45833, PYSEC-2026-3814
More Chroma advisories
All Chroma| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 12 | Chroma: insecure direct object reference | High8.8 | No fix yet |
| Jun 12 | Chroma: improper authorization | High8.8 | No fix yet |
| May 18 | ChromaDB Python project has a pre-authentication code injection vulnerability | Critical | No fix yet |