CVE-2026-45829Disclosure

HIGHCVSS 10.0 · CRITICAL

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 33 mentions across 8 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 30 signals
  • Disclosure: 22 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 10 mentions (2026-05-20); latest day: 1
  • 33 total mentions across 8 days

Deep dive

Activity timeline33 mentions / 8d
035810Mentions · 2026-05-18: 1Mentions · 2026-05-19: 6Mentions · 2026-05-20: 10Mentions · 2026-05-21: 10Mentions · 2026-05-22: 2Mentions · 2026-05-24: 1Mentions · 2026-05-25: 2Mentions · 2026-06-06: 1PoC Mentioned / Linked · 2026-05-19: 1PoC Mentioned / Linked · 2026-05-20: 2PoC Mentioned / Linked · 2026-05-21: 4PoC Mentioned / Linked · 2026-05-22: 1Exploit Tool / Code · 2026-05-21: 1Exploit Tool / Code · 2026-05-25: 1Active Exploitation · 2026-05-19: 1Active Exploitation · 2026-05-20: 2Active Exploitation · 2026-05-21: 1Active Exploitation · 2026-05-25: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-22: 1Patch / Workaround · 2026-05-25: 1Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 10Technical Details · 2026-05-21: 10Technical Details · 2026-05-22: 2Technical Details · 2026-05-24: 1Technical Details · 2026-05-25: 2Technical Details · 2026-06-06: 105-1805-1905-2005-2105-2205-2405-2506-06
Signal classification6 categories
Disclosure
2266.7%
Active Exploitation
515.2%
General
26.1%
PoC
26.1%
Exploit
13.0%
Patch
13.0%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-05-181
Disclosure1
2026-05-196
Active Exploitation1Disclosure3General1PoC1
2026-05-2010
Active Exploitation2Disclosure7PoC1
2026-05-2110
Active Exploitation1Disclosure8Exploit1
2026-05-222
Disclosure1Patch1
2026-05-241
Disclosure1
2026-05-252
Active Exploitation1Disclosure1
2026-06-061
General1
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    CVE-2026-45829: ChromaToast Served Pre-Auth Demo Demonstration of CVE-2026-45829 from the "ChromaToast Served Pre-Auth" blog. https://t.co/WJC5MqwDfT

    Post summary

    A public demonstration of CVE-2026-45829 is available via a blog link, but no exploit code, active exploitation, patch, or detailed technical data is disclosed.

    85033117.7K
    223.7K followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-45829 (CVSS 10.0): ChromaDB pre-auth RCE via malicious Hugging Face model refs 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJDaHJvbWEtQ2hyb21hREIi 🎯4.5K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="Chroma-ChromaDB" 🔖Refer: https://www.hiddenlayer.com/research/chromatoast-served-pre-auth #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The post announces a critical CVE‑2026‑45829 in ChromaDB, citing a research article and FOFA findings to highlight widespread exposure, but it does not provide a functional exploit or patch.

    0301031.5K
    14.4K followersView on X
  • AISecHub@AISecHub
    Active Exploitation

    AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829
📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291
📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291
📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/
📌 https://red.anthropic.com/2026/cvd/
📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity

    Post summary

    The digest highlights newly disclosed vulnerabilities such as ChromaDB’s code execution flaw and Langflow’s account takeover flaw now listed in the CISA KEV, details Anthropic’s Mythos research, and notes Mozilla’s patching of related Firefox bugs.

    140821.0K
    9.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Critical CVE-2026-45829 in ChromaDB allows unauthenticated remote code execution via malicious HuggingFace models. Authentication runs AFTER model loading, enabling pre-auth RCE. 73% of internet-exposed instances vulnerable. #DFIR_Radar https://t.co/qszdq3UELV

    Post summary

    The tweet announces a critical CVE‑2026‑45829 in ChromaDB, explaining that unauthenticated RCE is possible through malicious HuggingFace models and noting that roughly 73% of internet‑exposed instances are vulnerable.

    10030183
    1.8K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Disclosure

    یک آسیب‌پذیری با بالاترین سطح شدت (CVE-2026-45829) در نسخه Python FastAPI پروژه ChromaDB کشف شده است که به مهاجمان احراز هویت‌نشده اجازه می‌دهد کدهای دلخواه را روی سرورهای در معرض دسترسی اجرا کنند. این نقص توسط شرکت HiddenLayer کشف و در ۱۷ فوریه به ChromaDB گزارش شد. ChromaDB یک پایگاه داده برداری (vector database) متن‌باز است که در برنامه‌های هوش مصنوعی عاملی (agentic AI) و مدل‌های زبانی بزرگ (LLM) کاربرد دارد و بسته PyPI آن نزدیک به ۱۴ میلیون بارگیری ماهانه دارد. طبق یافته‌های محققان، یک نقطه پایانی (API endpoint) آسیب‌پذیر به مهاجم اجازه می‌دهد پیش از انجام احراز هویت، تنظیمات مدل را تزریق کند و ChromaDB را مجبور سازد یک مدل مخرب از پلتفرم Hugging Face بارگذاری و اجرا کند؛ در حالی که بررسی احراز هویت تنها پس از اجرای کد صورت می‌گیرد.

    Post summary

    A high‑severity vulnerability (CVE‑2026‑45829) in ChromaDB’s Python FastAPI endpoint permits unauthenticated attackers to inject model settings and execute arbitrary code, as disclosed by HiddenLayer.

    00013364
    18.8K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    ChromaDBに未修正のCVSSスコア10脆弱性。CVE-2026-45829はPythonのFastAPIサーバーで、ユーザーが制御するエンベディング関数の設定をアクセス権限を確認前にインスタンス化可能なもの。遠隔コード実行。細工されたHugging Faceリポを指す無認証リクエストでGG。 https://securityonline.info/chromadb-pre-auth-rce-vulnerability-cve-2026-45829/

    Post summary

    The post announces CVE-2026-45829 as a high‑risk (CVSS 10) remote code execution flaw in ChromaDB’s FastAPI server, caused by improper authentication checks on user‑controlled embeddings, with a PoC link referenced.

    00021975
    7.6K followersView on X
  • Orca Security@orcasec
    Disclosure

    🚨 Critical Pre-Auth RCE in ChromaDB Threatens AI Infrastructure CVE-2026-45829 (CVSS 10.0) allows unauthenticated attackers to execute arbitrary code on ChromaDB servers. 73% of exposed instances are vulnerable. Full breakdown and how Orca can help: https://orca.security/resources/blog/chromadb-pre-auth-rce-vulnerability/?utm_source=twitter&utm_medium=organic+social&utm_campaign=orca+blog https://t.co/0ZseMZLuDg

    Post summary

    A critical pre‑authentication RCE (CVE‑2026‑45829) affecting ChromaDB servers has been disclosed, with 73% of exposed instances vulnerable; a blog post provides analysis but no evidence of active exploitation or available patches.

    00020123
    4.8K followersView on X
  • Gray Hats@the_yellow_fall
    Exploit

    HiddenLayer exposes a CVSS 10.0 unpatched RCE vulnerability (CVE-2026-45829) in ChromaDB affecting 73% of exposed servers. Learn how to mitigate the risk. #ChromaDB #CVE202645829 #VectorDatabase #AISecurity #RemoteCodeExecution #FastAPI #HuggingFace https://meterpreter.org/chromatoast-exploit-unpatched-cvss-10-0-flaw-grants-pre-auth-rce-in-chromadb-python-server/ https://t.co/mYSrHrcB0P

    Post summary

    CVE‑2026‑45829 is a CVSS 10 unpatched RCE in ChromaDB with a publicly referenced exploit available, but there is no evidence of active exploitation in the wild.

    00011237
    12.2K followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVSS 10 🔥 CVE-2026-45829 in ChromaDB (pypi) is pre-auth code injection — no credentials needed to hijack the server. If you're running chromadb ≥1.0.0 in any AI stack, treat this as urgent. #AI #AppSec https://secalerts.co/vulnerability/CVE-2026-45829

    Post summary

    CVE-2026-45829 in ChromaDB presents a pre-auth code injection flaw with CVSS 10, affecting all versions ≥1.0.0, requiring urgent remediation.

    0000175
    826 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    ChromaDB CVE-2026-45829 hands pre-auth RCE: model-loading params set before auth, server then fetches a malicious model from Hugging Face. Model registry becomes the attack vector.

    Post summary

    The text announces the discovery of CVE-2026-45829 in ChromaDB, a pre-authentication remote code execution vulnerability caused by malicious models loaded from the Hugging Face registry.

    01000161
    575 followersView on X
  • NOCTIS@NoctisIntel
    Patch

    CVE-2026-45829 — ChromaDB pre-auth RCE. CVSS 10.0. FastAPI auth bypass → unauthenticated full server compromise. Hits LangChain, AutoGen, CrewAI, all RAG stacks. Firewall port 8000/tcp. Patch now. #ThreatIntel #CVE #ZeroDay #CVE202645829

    Post summary

    CVE-2026-45829 is a high‑severity pre‑authentication remote code execution in ChromaDB (CVSS 10.0) that can compromise multiple RAG stacks; a patch is now available and should be applied immediately.

    00010214
    28 followersView on X
  • キタきつね@foxbook
    Disclosure

    未修正のCVSS 10警告:ChromaDB Pythonサーバーが、悪意のあるハグ顔モデルを介して認証前のリモートコード実行(RCE)を許諾する Unpatched CVSS 10 Alert: ChromaDB Python Server Grants Pre-Auth RCE via Malicious Hugging Face Models #DailyCyberSecurity (May 21) https://securityonline.info/chromadb-pre-auth-rce-vulnerability-cve-2026-45829/

    Post summary

    The post alerts about an unpatched CVE-2026-45829 in ChromaDB Python Server that allows pre‑auth remote code execution through malicious Hugging Face models, with a CVSS score of 10.

    00010234
    4.9K followersView on X
  • InnoScout@innoscoutpro
    Disclosure

    ChromaDB just turned AI memory into a remote-code surface. HiddenLayer says CVE-2026-45829 lets unauthenticated attackers reach code execution through ChromaDB’s collection-creation path when trusted remote embedding code is enabled. The weak point is brutal. Vector stores sit close to prompts, documents, API traces, and agent memory, so a database bug becomes a model-context breach. Competitors and bot crews can turn public AI apps into collection probes. Customers and internal datasets take the hit. Source links are in the replies.

    Post summary

    CVE‑2026‑45829 in ChromaDB permits unauthenticated attackers to achieve remote code execution through the collection‑creation path when remote embedding code is enabled, exposing AI memory as a remote code surface; source links for further detail are provided.

    1000050
    38 followersView on X
  • Rory J. Bernier@RoryCrave
    Disclosure

    CVE-2026-45829 — ChromaDB Python server hands you RCE before it asks who you are https://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are

    Post summary

    The blog post announces CVE‑2026‑45829, revealing a remote code‐execution flaw in the ChromaDB Python server that occurs before authentication, but it provides no patch, tool, or evidence of active exploitation.

    0000176
    2.9K followersView on X
  • su8 / denchu@__su888
    Disclosure

    AIアプリ向けベクトルDB「ChromaDB」に認証前RCE脆弱性「ChromaToast」(CVE-2026-45829)。悪意あるHuggingFaceモデルで任意コード実行可能、公開インスタンスの73%が影響、v1.5.8でも未修正 / Max severity flaw in ChromaDB for AI apps allows server hijacking https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/

    Post summary

    A new authentication‑pre RCE vulnerability (CVE‑2026‑45829) in ChromaDB, affecting the majority of public instances and currently unpatched in v1.5.8, has been publicly disclosed as a high‑severity flaw.

    00010126
    792 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Unpatched ChromaDB flaw CVE-2026-45829, dubbed ChromaToast, enables pre-auth RCE via malicious HuggingFace models, risking server takeover and exposure of API keys, env vars, and secrets. #ChromaDB #CVE202645829 #ChromaToast https://ift.tt/N1PX4SB

    Post summary

    The post announces CVE-2026-45829 in ChromaDB, detailing a pre‑authentication RCE via malicious HuggingFace models, but offers no proof‑of‑concept, exploit code, or evidence of active exploitation.

    00010114
    4.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『This allows an unauthenticated attacker with HTTP API access to trigger remote code execution (RCE) by supplying a malicious HuggingFace model reference,』😨 CVE-2026-45829 ChromaToast Served Pre-Auth https://www.hiddenlayer.com/research/chromatoast-served-pre-auth

    Post summary

    The text discloses that CVE-2026-45829 allows an unauthenticated attacker to trigger remote code execution via a malicious HuggingFace model reference; no PoC, exploit, or patch is provided.

    00001414
    6.9K followersView on X
  • TodayInCyber@TodayInCyberIO
    General

    🔴 CRITICAL | A critical vulnerability, CVE-2026-45829 (ChromaToast), has been discovered in the open-source vector database ChromaDB #vulnerability #CVE202645829 #cybersecurity https://todayincyber.io/feed/vulnerability/article/019e4054-3213-7a95-96fc-697fbdde82fc

    Post summary

    The tweet merely announces the discovery of CVE‑2026‑45829 in ChromaDB, without providing PoC, exploitation details, or mitigation information.

    000105
    8 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-45829: ChromaDB Pre-Auth Code Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04kp9SR0

    Post summary

    The headline references CVE‑2026‑45829 as a pre‑authorization code‑injection flaw in ChromaDB, but provides no further details on PoC, exploit code, active attacks, or patching.

    0000024
    32 followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    🔴 CRITICAL | A critical pre-authentication Remote Code Execution (RCE) vulnerability, CVE-2026-45829, has been disclosed in ChromaDB, a popular open-source vector database used in AI applications #vulnerability #CVE202645829 #cybersecurity https://todayincyber.io/feed/vulnerability/article/019e4c7a-390b-7d9c-9563-cd0d9272b33e

    Post summary

    The post announces the disclosure of a critical pre‑authentication RCE vulnerability (CVE‑2026‑45829) affecting ChromaDB.

    000002
    8 followersView on X

Explore more