Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-45829

3 месяца назад

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

CVSS3: 10
EPSS: Средний
nvd логотип

CVE-2026-45829

3 месяца назад

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

EPSS: Средний
github логотип

GHSA-f4j7-r4q5-qw2c

3 месяца назад

ChromaDB Python project has a pre-authentication code injection vulnerability

EPSS: Средний
fstec логотип

BDU:2026-07111

6 месяцев назад

Уязвимость прикладного программного интерфейса системы управления базами данных ChromaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

CVSS3: 10
10%
Средний
3 месяца назад
nvd логотип
CVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

10%
Средний
3 месяца назад
github логотип
GHSA-f4j7-r4q5-qw2c

ChromaDB Python project has a pre-authentication code injection vulnerability

10%
Средний
3 месяца назад
fstec логотип
BDU:2026-07111

Уязвимость прикладного программного интерфейса системы управления базами данных ChromaDB, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
10%
Средний
6 месяцев назад

Уязвимостей на страницу