Max-severity flaw in ChromaDB for AI apps allows server hijacking
ID: bbe8df79-4264-5c16-b9ad-9feecfcc376d
STIX ID: report--bbe8df79-4264-5c16-b9ad-9feecfcc376d
Feed Name: Bleeping Computer
Threat Score
A maximum-severity vulnerability (CVE-2026-45829) in ChromaDB's Python FastAPI API server lets unauthenticated attackers force the service to load and execute malicious models before authentication is enforced, enabling arbitrary code execution on exposed servers; many internet-facing instances appear vulnerable and recommended mitigations include using the Rust frontend, not exposing the Python server, restricting network access, and scanning model artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
