Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45829

Опубликовано: 18 мая 2026
Источник: nvd
CVSS3: 10
EPSS Средний

Описание

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

EPSS

Процентиль: 96%
0.12387
Средний

10 Critical

CVSS3

Дефекты

CWE-94
CWE-502

Связанные уязвимости

CVSS3: 10
redhat
3 месяца назад

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

github
3 месяца назад

ChromaDB Python project has a pre-authentication code injection vulnerability

CVSS3: 10
fstec
6 месяцев назад

Уязвимость прикладного программного интерфейса системы управления базами данных ChromaDB, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.12387
Средний

10 Critical

CVSS3

Дефекты

CWE-94
CWE-502