Chroma through 1.5.9 Authorization Bypass via Collection Identifier
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.6epss 0.3%
exploitation probability
0.3%top 83% of all CVEs
observed exploitation
nono source reports it
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
chroma-core · chromaReferences
https://github.com/chroma-core/chromahttps://github.com/chroma-core/chroma/blob/1.5.9/rust/frontend/src/get_collection_with_segments_provider.rs#L143-L160https://github.com/chroma-core/chroma/blob/1.5.9/rust/frontend/src/server.rs#L469-L487https://github.com/chroma-core/chroma/issues/7462https://www.vulncheck.com/advisories/chroma-through-1.5.9-authorization-bypass-via-collection-identifier