ChromaDB Pre-Auth RCE (CVE-2026-45829)

Cloud Security Alliance (CSA) pdf 2026-05-21T00:00:00

Abstract

CVE-2026-45829 ("ChromaToast") is a CVSS 10.0 pre-authentication remote code execution vulnerability in ChromaDB's Python FastAPI server, affecting versions 1.0.0 through 1.5.8. An unauthenticated attacker with HTTP access to the API port can achieve full server compromise by supplying a malicious HuggingFace model reference in a collection creation request, gaining a shell with the privileges of the database process.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD