Threat Intelligence / CVE / CVE-2026-45829
CVE-2026-45829
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.
Weaknesses (CWE)
CWE-94
Threats tracking this CVE
References
- https://www.hiddenlayer.com/research/chromatoast-served-pre-auth
- https://github.com/chroma-core/chroma/issues/6717
Full detection coverage & IOCs for threats exploiting CVE-2026-45829 are available via the Threadlinqs MCP server (Purple tier). View plans →