Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models
ID: 80f8dd1a-486b-552d-b234-596430e44571
STIX ID: report--80f8dd1a-486b-552d-b234-596430e44571
Feed Name: securityonline.info
ChromaDB has a critical unauthenticated RCE (CVE-2026-45829, CVSS 10.0) caused by initializing user-controlled embedding model configuration before performing authentication; an attacker can supply a poisoned Hugging Face model that is pulled and executed (via trust_remote_code) leading to full server compromise. HiddenLayer’s technical report documents the root cause, notes the bug was introduced in v1.0.0 and remains unpatched through v1.5.8, and Shodan-based scans show a large portion of internet-exposed instances are in the vulnerable version range.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
