vulnerability Max-severity flaw in ChromaDB for AI apps allows server hijacking A critical vulnerability (CVE-2026-45829) has been identified in the ChromaDB project, allowing unauthenticated attackers to execute arbitrary code on exposed servers. This flaw stems from a misplacement of authentication checks within the FastAPI API server, enabling attackers to load and run malicious models from pla… BleepingComputer · May 19, 2026 Critical CVE-2026-45829apipythonfastapi