Sploitus

CVE-2026-45833

1 known exploit for CVE-2026-45833

A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.

Affected products
Chromadb
Trychroma Chromadb
≤ 1.5.9
Fix
Available
CVSS 4.0
9.4 CRITICAL
CVSS 3.1
8.8 HIGH
EPSS
0.3% (27th percentile)
Weakness
CWE-94
NVD status
Modified
Published
2026-06-12
Attack patterns
CAPEC-242
Entry point
trust_remote_code request body
Path
/api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id}
CVE-2026-45833 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-45833

Proof-of-concept code and exploit modules indexed by Sploitus