Skip to main content

Vendor/product archive

trychroma / chromadb CVEs

Beta · best-effort

4 CVEs tagged to trychroma / chromadb1 Critical, 3 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-45833

Published Jun 12, 2026

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a maliciou…

CVSS 9.4 · Critical
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-45832

Published Jun 12, 2026

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization control…

CVSS 8.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort

CVE-2026-45831

Published Jun 12, 2026

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never ch…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-45830

Published Jun 12, 2026

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in a…

CVSS 8.8 · High
evidence mentions
4
Buzz score
32.6
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1