Executive brief
ChromaDB is an open-source vector database used to store and manage data for AI applications. A security flaw in its legacy V1 interface allows any logged-in user to bypass data isolation controls. This means an attacker could view or modify private data belonging to other customers or departments, potentially leading to large-scale data breaches or unauthorized data manipulation.
Technical details
A missing authorization vulnerability exists in ChromaDB's FastAPI implementation within `chromadb/server/fastapi/__init__.py`. The V1 collection-level endpoints (such as add_v1 and get_v1) systematically pass `None` for the tenant and database parameters when calling the authorization sync method. This causes the `AuthzResource` to be initialized without tenant context, rendering tenant-scoped access controls ineffective regardless of the configured authorization provider. An authenticated attacker can exploit this by targeting collections via their UUID through these V1 endpoints to achieve unrestricted read/write access across the entire database. As of the advisory date, the V1 API cannot be disabled, and no patch has been confirmed by the vendor.
Affected products
- ChromaDB ChromaDB 0.5.0 to latest Python release
Timeline
- 2026-02-17: disclosed: Initial disclosure to ChromaDB security team
- 2026-06-12: advisory: Public disclosure by HiddenLayer