Threat Intelligence / CVE / CVE-2026-45829

CVE-2026-45829

CVSS 10 · EPSS 0.2% · Published 2026-05-18

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

Weaknesses (CWE)

CWE-94

Threats tracking this CVE

References

Full detection coverage & IOCs for threats exploiting CVE-2026-45829 are available via the Threadlinqs MCP server (Purple tier). View plans →

Markdown version · Threadlinqs Intelligence