logo

Max-severity flaw in ChromaDB for AI apps allows server hijacking

ID: bbe8df79-4264-5c16-b9ad-9feecfcc376d

STIX ID: report--bbe8df79-4264-5c16-b9ad-9feecfcc376d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Bill Toulas

...
...

A maximum-severity vulnerability (CVE-2026-45829) in ChromaDB's Python FastAPI API server lets unauthenticated attackers force the service to load and execute malicious models before authentication is enforced, enabling arbitrary code execution on exposed servers; many internet-facing instances appear vulnerable and recommended mitigations include using the Rust frontend, not exposing the Python server, restricting network access, and scanning model artifacts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.