A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in theĀ /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.
{
"cna_assigner": "HiddenLayer",
"cwe_ids": [
"CWE-94"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45833.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.4.17"
},
{
"last_affected": "*"
}
],
"source": "AFFECTED_FIELD"
}
]
}