{"data":{"ecosystem":"npm","name":"chromadb","url":"https://aisecwatch.com/packages/npm/chromadb","latestVersion":"3.5.0","firstReleaseAt":"2023-02-14T05:47:15.680Z","repository":null,"llm":{"exposure":"direct","depth":0,"integratedAt":"2023-02-14T05:47:15.680Z","integratedVersion":"1.0.0","sdks":["chromadb"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"npm","name":"semver","versionSpec":"^7.7.1","scope":"runtime"}],"advisories":[{"id":"551f077d-092e-4c44-a65c-3b2307c30608","url":"https://aisecwatch.com/issues/551f077d-092e-4c44-a65c-3b2307c30608","cveId":"CVE-2026-45833","title":"CVE-2026-45833: A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated…","headline":"ChromaDB code injection through collection update API","severity":"critical","publishedAt":"2026-06-12T16:16:29.070Z","affected":["chromadb@>= 0.4.17, <= 1.5.9"],"epssScore":0.00626},{"id":"d61b1747-7db7-4f42-8140-5cb6cb4a3f8b","url":"https://aisecwatch.com/issues/d61b1747-7db7-4f42-8140-5cb6cb4a3f8b","cveId":"CVE-2026-45831","title":"CVE-2026-45831: The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project…","headline":"ChromaDB SimpleRBACAuthorizationProvider skips tenant and collection scope","severity":"high","publishedAt":"2026-06-12T16:16:28.797Z","affected":["chromadb@>= 0.5.0, <= 1.5.9"],"epssScore":0.00422},{"id":"ddb4679b-e903-4693-9ef6-542e94971b61","url":"https://aisecwatch.com/issues/ddb4679b-e903-4693-9ef6-542e94971b61","cveId":"CVE-2026-45830","title":"CVE-2026-45830: A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated…","headline":"ChromaDB Python authorization flaw allows cross-tenant data access","severity":"high","publishedAt":"2026-06-12T16:16:28.660Z","affected":["chromadb@>= 0.4.17, <= 1.5.9"],"epssScore":0.00495},{"id":"7b1eded0-bda4-4312-9dc1-891f425f7bc7","url":"https://aisecwatch.com/issues/7b1eded0-bda4-4312-9dc1-891f425f7bc7","cveId":"CVE-2026-45829","title":"CVE-2026-45829: A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an…","headline":"ChromaDB pre-authentication code injection via collections endpoint","severity":"critical","publishedAt":"2026-05-18T17:16:34.040Z","affected":["chromadb@>= 1.0.0, <= 1.5.9"],"epssScore":0.01023}],"checkedAt":"2026-10-09T21:52:04.118Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}