Max-severity flaw in ChromaDB for AI apps allows server hijacking - BleepingComputer
Max-severity RCE in ChromaDB. If your AI stack runs on it, your servers are exposed.

Why it matters
A critical, unauthenticated remote code execution vulnerability in ChromaDB—a foundational vector database for RAG and AI applications—poses immediate risk to production AI deployments. This is a governance and operational security issue every AI infrastructure leader needs to address now.
The key facts
7 to knowCVE-2026-45829
Max-severity / CVSS critical
Unauthenticated remote code execution (RCE)
Pre-auth vulnerability via HuggingFace integration
ChromaDB FastAPI / ChromaToast endpoint affected
Unpatched versions remain vulnerable
Affects foundational vector database layer for RAG pipelines
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: Max-severity flaw in ChromaDB for AI apps allows server hijacking BleepingComputer Unpatched ChromaDB Vulnerability Can Lead to Server Takeover SecurityWeek CVE-2026-45829: ChromaDB FastAPI ChromaToast RCE Exploit Now The Cyber Express ChromaDB: Critical vulnerability allows Pre-auth RCE via…