Skip to content

[SECURITY]: ChromaDB Python project has a pre-authentication code injection vulnerability #7226

@humanize-platform

Description

@humanize-platform

What happened?

Getting alert from Git:
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

How to address this issue? Are you publishing newer version by fixing this?

Versions

= 1.0.0, <= 1.5.9

Relevant log output

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions