Impact
Chroma through version 1.5.9 does not verify the tenant and database segments when resolving a collection, allowing an attacker who has authenticated access to read, modify or delete records in collections belonging to other tenants. This flaw enables the attacker to bypass normal authorization checks, effectively granting cross‑tenant access to data. The weakness corresponds to CWE‑863, which describes inadequate enforcement of authorization policies.
Affected Systems
Chroma Core (chroma‑core:chroma) – all releases up to and including 1.5.9 are affected. Users should check their installed version and apply the patch if they are running 1.5.9 or an earlier release.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the issue has not been listed in the CISA KEV catalog. Likely exploitation requires an authenticated user who knows the target collection identifier and can send requests under their own tenant path; the attacker then receives data from or modifies the foreign collection without permission.
OpenCVE Enrichment