
AI Security Digest | May 18-24, 2026 🔴 ChromaDB: unauthenticated code execution NVD published CVE-2026-45829 for ChromaDB. The bug affects the ChromaDB Python project starting with version 1.0.0. An unauthenticated attacker can send a malicious model repository with trust_remote_code=true to the collections API endpoint and execute code on the server. HiddenLayer assigned the issue a CVSS 4.0 score of 10.0. 📌 https://nvd.nist.gov/vuln/detail/CVE-2026-45829 📌 https://www.hiddenlayer.com/research/chromatoast-served-pre-auth 🟠 Langflow: exploited vulnerability added to CISA KEV CISA added CVE-2025-34291 in Langflow to the Known Exploited Vulnerabilities catalog on May 21. The vulnerability affects Langflow versions up to and including 1.6.9. NVD describes it as a chained issue involving permissive CORS and refresh-token cookie behavior that can lead to account takeover and remote code execution. 📌 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-34291 📌 https://nvd.nist.gov/vuln/detail/CVE-2025-34291 📌 https://github.com/advisories/GHSA-577h-p2hh-v4mv 🧪 Anthropic: Mythos used for vulnerability discovery Reuters reported that Anthropic planned to brief the Financial Stability Board on vulnerabilities identified by Claude Mythos. Anthropic also published a disclosure dashboard showing 1,596 vulnerabilities disclosed across 281 open-source projects as of May 22. 📌 https://www.reuters.com/technology/anthropic-brief-financial-stability-board-cyber-flaws-exposed-by-mythos-ft-2026-05-18/ 📌 https://red.anthropic.com/2026/cvd/ 📌 https://www.anthropic.com/research/glasswing-initial-update 🦊 Mozilla: Firefox bugs found during Claude Mythos evaluation Mozilla published details on its work with Anthropic’s Claude Mythos. Firefox 150 included fixes for vulnerabilities identified during the evaluation, grouped under CVE-2026-6784, CVE-2026-6785, and CVE-2026-6786. 📌 https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/ 📌 https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/ #AISecurity #CyberSecurity #AISECHUB #ChromaDB #Langflow #CISA #Anthropic #Mythos #Mozilla #Firefox #LLMSecurity
Post summary
The digest reports a new unauthenticated code‑execution flaw (CVE‑2026‑45829) in ChromaDB, confirms active exploitation of a Langflow vulnerability (CVE‑2025‑34291) via the CISA KEV catalog, and notes that Firefox 150 has patched multiple Mythos‑discovered vulnerabilities.


