-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from the use of eval() in the ChromaDB handler's insert function to process metadata values. The GitHub patch explicitly replaces eval() with ast.literal_eval() in this function, and the CVE description specifically calls out ChromaDB INSERT queries as the attack vector. While other handlers (SharePoint, Weaviate) also had eval() usages patched, CVE-2024-45848 is explicitly tied to the ChromaDB integration's metadata processing in the insert method.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mindsdb | pip | >= 23.12.4.0, < 24.7.4.1 | 24.7.4.1 |
Ongoing coverage of React2Shell