logo

Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models

ID: 80f8dd1a-486b-552d-b234-596430e44571

STIX ID: report--80f8dd1a-486b-552d-b234-596430e44571

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

Author: Ddos

...
...

ChromaDB has a critical unauthenticated RCE (CVE-2026-45829, CVSS 10.0) caused by initializing user-controlled embedding model configuration before performing authentication; an attacker can supply a poisoned Hugging Face model that is pulled and executed (via trust_remote_code) leading to full server compromise. HiddenLayer’s technical report documents the root cause, notes the bug was introduced in v1.0.0 and remains unpatched through v1.5.8, and Shodan-based scans show a large portion of internet-exposed instances are in the vulnerable version range.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.