FOFA[verified]@fofabotDisclosure
The post announces a critical CVE‑2026‑45829 in ChromaDB, citing a research article and FOFA findings to highlight widespread exposure, but it does not provide a functional exploit or patch.
AISecHub[verified]@AISecHubActive Exploitation
The digest highlights newly disclosed vulnerabilities such as ChromaDB’s code execution flaw and Langflow’s account takeover flaw now listed in the CISA KEV, details Anthropic’s Mythos research, and notes Mozilla’s patching of related Firefox bugs.
DFIR Radar[verified]@DFIR_RadarDisclosure
The tweet announces a critical CVE‑2026‑45829 in ChromaDB, explaining that unauthenticated RCE is possible through malicious HuggingFace models and noting that roughly 73% of internet‑exposed instances are vulnerable.
Teegra 🧝♀️𝕏[verified]@TeeegraDisclosure
A high‑severity vulnerability (CVE‑2026‑45829) in ChromaDB’s Python FastAPI endpoint permits unauthenticated attackers to inject model settings and execute arbitrary code, as disclosed by HiddenLayer.
kokumօtօ[verified]@__kokumotoDisclosure
The post announces CVE-2026-45829 as a high‑risk (CVSS 10) remote code execution flaw in ChromaDB’s FastAPI server, caused by improper authentication checks on user‑controlled embeddings, with a PoC link referenced.
PurpleOps[verified]@PurpleOps_ioDisclosure
The text announces the discovery of CVE-2026-45829 in ChromaDB, a pre-authentication remote code execution vulnerability caused by malicious models loaded from the Hugging Face registry.
キタきつね[verified]@foxbookDisclosure
The post alerts about an unpatched CVE-2026-45829 in ChromaDB Python Server that allows pre‑auth remote code execution through malicious Hugging Face models, with a CVSS score of 10.
InnoScout[verified]@innoscoutproDisclosure
CVE‑2026‑45829 in ChromaDB permits unauthenticated attackers to achieve remote code execution through the collection‑creation path when remote embedding code is enabled, exposing AI memory as a remote code surface; source links for further detail are provided.