© 2025-2026 PySpect
First version without a known vulnerability: 0.0.3.dev234
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
ChromaDB has a code injection vulnerability
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
ChromaDB Python project has a pre-authentication code injection vulnerability