Skip to content
ChromaGHSA-xph7-9rjv-w5fr

Chroma: improper authorization

High8.8CVE-2026-45831 · Published Jun 12, 2026 · updated Sep 10, 2026

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

GitHub advisory

Affected versions

PackageAffectedFixed in
chromadb
PyPI
>= 0.5.0, <= 1.5.9No fix yet
Details and references

More Chroma advisories

All Chroma
Advisory
Chroma: insecure direct object reference
High8.8Jun 12
ChromaDB has a code injection vulnerability
CriticalJun 12
ChromaDB Python project has a pre-authentication code injection vulnerability
CriticalMay 18

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.