A AegiFlow
CRITICALCVSS 9.4EPSS 0.3%

CVE-2026-45833

ChromaDB has a code injection vulnerability

Published
2026-06-12
Modified
2026-08-24
EPSS percentile
27%
Aliases
GHSA-36p7-vc44-83pf
Sources
github-advisory

Summary

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIchromadb

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.