REDHAT-BUG-2479623: Code Injection
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trustremotecode set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2479623?
The severity of REDHAT-BUG-2479623 is rated at 92, indicating a high risk level.
How can I fix REDHAT-BUG-2479623?
To fix REDHAT-BUG-2479623, update to version 1.0.1 or later of the ChromaDB Python project.
What systems are affected by REDHAT-BUG-2479623?
REDHAT-BUG-2479623 affects any systems using version 1.0.0 or later of the ChromaDB Python project.
What does REDHAT-BUG-2479623 exploit?
REDHAT-BUG-2479623 exploits a pre-authentication code injection vulnerability allowing arbitrary code execution.
When was REDHAT-BUG-2479623 published?
REDHAT-BUG-2479623 was published on May 18, 2026.