CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2026-45833

PENDING
N/A
CVSS Severity Score
EPSS Score0.0180%
EPSS Percentile30.69th
Published2026年6月12日
Last Modified2026年6月12日

Vulnerability Description

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相關漏洞威脅