Skip to content

🚨 Security: Critical issues in chroma-mcp container #273

@github-actions

Description

@github-actions

🚨 Security Scan Alert

A periodic security scan found critical issues in the container image:

  • Image: ghcr.io/stacklok/dockyard/uvx/chroma-mcp:0.2.6
  • Critical vulnerabilities: 1
  • High vulnerabilities: 5
  • Secrets detected: 0

Details

See the Security tab for full details.

Critical Vulnerabilities

  • CVE-2025-68664 in langchain-core: langchain-core: LangChain: Arbitrary code execution via serialization injection

Automated security scan from periodic-security-scan workflow

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions