ChromaDB Releases • 11w
The 1.5.8 Versioning Crisis: Critical RCE and Data Exposure Risks
A critical convergence of vulnerabilities affecting version 1.5.8 across disparate software ecosystems—specifically ChromaDB, Roundcube, and medical imaging tools—has created a high-risk attack surface for enterprise environments. The most severe threat involves a Remote Code Execution (RCE) flaw within ChromaDB’s AI vector database infrastructure and the emergence of CVE-2025-57283, potentially allowing threat actors to hijack AI workloads or exfiltrate Protected Health Information (PHI) from DICOM viewers. Organizations must immediately audit their version manifests and apply the latest security patches to prevent unauthorized infrastructure access and catastrophic data leakage.
Links:ChromaDB Releases, Wpscan, Labs, Hipaajournal, Sentinelone, Roundcube •