Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trychroma
Trychroma chromadb |
|
| CPEs | cpe:2.3:a:trychroma:chromadb:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Trychroma
Trychroma chromadb |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 15 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Execution via Trust-Remote-Code in ChromaDB 0.4.17+ | chromadb: ChromaDB: Arbitrary Code Execution via Code Injection |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 12 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Code Execution via Trust-Remote-Code in ChromaDB 0.4.17+ | |
| First Time appeared |
Chroma
Chroma chromadb |
|
| Vendors & Products |
Chroma
Chroma chromadb |
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission. | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2026-06-30T12:10:16.852Z
Reserved: 2026-05-13T14:01:39.604Z
Link: CVE-2026-45833
Updated: 2026-06-30T03:20:38.613Z
Status : Analyzed
Published: 2026-06-12T16:16:29.070
Modified: 2026-06-16T15:03:10.113
Link: CVE-2026-45833
OpenCVE Enrichment
Updated: 2026-06-12T16:30:14Z