news.mlab.sh
Back to the feed
vulnerability

Max-severity flaw in ChromaDB for AI apps allows server hijacking

Critical
Summary

A critical vulnerability (CVE-2026-45829) has been identified in the ChromaDB project, allowing unauthenticated attackers to execute arbitrary code on exposed servers. This flaw stems from a misplacement of authentication checks within the FastAPI API server, enabling attackers to load and run malicious models from platforms like Hugging Face. The vulnerability poses a significant risk to applications utilizing ChromaDB, particularly those with publicly accessible API servers.

Read the full article at BleepingComputer

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.