chromadb@0.1.dev363

Chroma.

Direct Vulnerabilities

Known vulnerabilities in the chromadb package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • C
Deserialization of Untrusted Data

chromadb is a Chroma.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the trust_remote_code process. An attacker can execute arbitrary code on the server by sending a malicious model repository to the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint. This is only exploitable if trust_remote_code is set to true.

How to fix Deserialization of Untrusted Data?

There is no fixed version for chromadb.

[0,)