PYSEC-2026-3814

    Dashboard / Vulnerabilities / PYSEC-2026-3814

    PYSEC-2026-3814

    Published: 10 Sept 2026Last Modified: 10 Sept 2026

    Summary: ChromaDB has a code injection vulnerability

    Details: A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

    Affected packages

    Package

    Name: chromadb

    Purl: pkg:pypi/chromadb

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0.4.17
    Fixed -None

    Affected versions

    0.4.17
    0.4.18
    0.4.19
    0.4.20
    0.4.21
    0.4.22
    0.4.23
    0.4.24

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    PYSEC-2026-3814 | CVE-DB