Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36p7-vc44-83pf

Опубликовано: 12 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.4
CVSS3: 8.8

Описание

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

EPSS

Процентиль: 27%
0.00342
Низкий

9.4 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 месяцев назад

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

CVSS3: 8.8
nvd
около 2 месяцев назад

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

EPSS

Процентиль: 27%
0.00342
Низкий

9.4 Critical

CVSS4

8.8 High

CVSS3

Дефекты

CWE-94