Disclosure summary
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-f4j7-r4q5-qw2c
Open original source · Updated Oct 05, 2026
ChromaDB Python project has a pre-authentication code injection vulnerability
Source severity: CRITICAL / 9.3
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | chromadb | >= 1.0.0, | Not supplied |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-05-18T14:31:30-04:00
MODIFIED 2026-10-05T17:32:32-04:00
INGESTED 2026-10-06T11:45:33-04:00