Chroma security advisories
4 advisories · 4 critical or high in 12 months · latest Jun 12
4 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 12 | ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection CVE-2026-45830High8.8no fix yet | High8.8 | No fix yet |
| Jun 12 | ChromaDB has a code injection vulnerability CVE-2026-45833Criticalno fix yet | Critical | No fix yet |
| Jun 12 | ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to CVE-2026-45831High8.8no fix yet | High8.8 | No fix yet |
| May 18 | ChromaDB Python project has a pre-authentication code injection vulnerability CVE-2026-45829Criticalno fix yet | Critical | No fix yet |