CVE Feed

    Dashboard / CVE / CVE-2026-45833

    CVE-2026-45833

    A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

    Published:Jun 12, 2026
    Last Modified:Jun 16, 2026
    EPS:Jun 12, 2026
    EPSS Score:0.00256
    CVSS Score:8.8

    Affected Products

    Vendor
    Chroma
    Product
    Chromadb
    Vendor
    Trychroma
    Product
    Chromadb

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High