Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4j7-r4q5-qw2c

Опубликовано: 18 мая 2026
Источник: github
Github: Прошло ревью
CVSS4: 9.3

Описание

ChromaDB Python project has a pre-authentication code injection vulnerability

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

Пакеты

Наименование

chromadb

pip
Затронутые версииВерсия исправления

>= 1.0.0, <= 1.5.9

Отсутствует

EPSS

Процентиль: 96%
0.12387
Средний

9.3 Critical

CVSS4

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 10
redhat
3 месяца назад

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

CVSS3: 10
nvd
3 месяца назад

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

CVSS3: 10
fstec
6 месяцев назад

Уязвимость прикладного программного интерфейса системы управления базами данных ChromaDB, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.12387
Средний

9.3 Critical

CVSS4

Дефекты

CWE-94