PT-2026-48898 · Chroma · Chromadb

Published

2026-06-12

·

Updated

2026-06-12

·

CVE-2026-45833

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust remote code set to true in the /api/v2/tenants/default tenant/databases/default database/collections/{collection id} if they have the UPDATE COLLECTION permission.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-45833

Affected Products

Chromadb