Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3815
  • PyPI/chromadb
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to 10 Sep
  • No fix available
  • Severity - 8.8 (High)
PYSEC-2026-3814
  • PyPI/chromadb
ChromaDB has a code injection vulnerability 10 Sep
  • No fix available
  • Severity - 9.4 (Critical)
PYSEC-2026-3813
  • PyPI/chromadb
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection 10 Sep
  • No fix available
  • Severity - 8.8 (High)
PYSEC-2026-311
  • PyPI/chromadb
ChromaDB Python project has a pre-authentication code injection vulnerability 29 Jun
  • No fix available
  • Severity - 9.3 (Critical)
GHSA-2wm9-hf6c-p5cr
  • PyPI/chromadb
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection 12 Jun
  • No fix available
  • Severity - 8.8 (High)
GHSA-36p7-vc44-83pf
  • PyPI/chromadb
ChromaDB has a code injection vulnerability 12 Jun
  • No fix available
  • Severity - 9.4 (Critical)
GHSA-xph7-9rjv-w5fr
  • PyPI/chromadb
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to 12 Jun
  • No fix available
  • Severity - 8.8 (High)
GHSA-f4j7-r4q5-qw2c
  • PyPI/chromadb
ChromaDB Python project has a pre-authentication code injection vulnerability 18 May
  • No fix available
  • Severity - 9.3 (Critical)