VDB
EN
CRITICAL

GHSA-f4j7-r4q5-qw2c

ChromaDB Python project has a pre-authentication code injection vulnerability

상세

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / chromadb
최초 영향 버전: 1.0.0

No fixed version published yet for chromadb (pip). Pin to a known-safe version or switch to an alternative.

참고