CVE-2026-45829
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.
- Affected products
- Chromadb
- Fix
- Available
- CVSS 4.0
- 10.0 CRITICAL
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 12.4% (96th percentile)
- Weakness
- CWE-94, CWE-502
- NVD status
- Awaiting Analysis
- Published
- 2026-05-18
- Attack patterns
- CAPEC-242
- Entry point
- embedding_function request body
- Path
- /api/v2/tenants/{tenant}/databases/{db}/collections
CVE-2026-45829 at NVD
4 known exploits for CVE-2026-45829
Proof-of-concept code and exploit modules indexed by Sploitus