ChromaDB Pre-Auth RCE (CVE-2026-45829)
Cloud Security Alliance (CSA)
pdf
2026-05-21T00:00:00
Abstract
CVE-2026-45829 ("ChromaToast") is a CVSS 10.0 pre-authentication remote code execution vulnerability in ChromaDB's Python FastAPI server, affecting versions 1.0.0 through 1.5.8. An unauthenticated attacker with HTTP access to the API port can achieve full server compromise by supplying a malicious HuggingFace model reference in a collection creation request, gaining a shell with the privileges of the database process.
Loading executive summary...
Loading full markdown...
Match Rate:
10.00/10
(Relevance to core cybersecurity goals)