GHSA-xph7-9rjv-w5fr
Dashboard / Vulnerabilities / GHSA-xph7-9rjv-w5fr
GHSA-xph7-9rjv-w5fr
Summary: ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
Details: The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-45831, https://github.com/chroma-core/chroma/issues/7588, https://github.com/chroma-core/chroma/pull/7602, https://github.com/chroma-core/chroma, https://www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3
Affected packages
Package
Name: chromadb
Purl: pkg:pypi/chromadb
Affected ranges
Type: ECOSYSTEM
Events:
