Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45833

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 8.8
CVSS3: 7.5
EPSS Низкий

Описание

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trychroma:chromadb:*:*:*:*:*:python:*:*
Версия от 0.4.17 (включая) до 1.5.9 (включая)

EPSS

Процентиль: 26%
0.00342
Низкий

8.8 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 7.5
redhat
около 2 месяцев назад

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

CVSS3: 8.8
github
около 2 месяцев назад

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

EPSS

Процентиль: 26%
0.00342
Низкий

8.8 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-94
CWE-94