logo

Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution

ID: 958b925b-59fb-5c2b-af1c-6ccb9f8f63ec

STIX ID: report--958b925b-59fb-5c2b-af1c-6ccb9f8f63ec

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2026-05-20

Date Updated: 2026-05-20

Author: Ashish Khaitan

...
...

ChromaDB's FastAPI server has an authentication-ordering flaw (CVE-2026-45829, 'ChromaToast') that processes client-supplied embedding configuration and loads HuggingFace models before enforcing authentication; with trust_remote_code enabled an attacker can achieve unauthenticated remote code execution on versions 1.0.0–1.5.8. The report documents a demonstration, indicates widespread exposure (~73% of internet-facing instances scanned), outlines severe impacts (process takeover, secret/data access, lateral movement), and recommends mitigations such as using the Rust deployment, restricting network exposure, and avoiding external model references.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.