Sploitus

CVE-2026-45829

4 known exploits for CVE-2026-45829

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

Affected products
Chromadb
Fix
Available
CVSS 4.0
10.0 CRITICAL
CVSS 3.1
10.0 CRITICAL
EPSS
12.4% (96th percentile)
Weakness
CWE-94, CWE-502
NVD status
Awaiting Analysis
Published
2026-05-18
Attack patterns
CAPEC-242
Entry point
embedding_function request body
Path
/api/v2/tenants/{tenant}/databases/{db}/collections
CVE-2026-45829 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2026-45829

Proof-of-concept code and exploit modules indexed by Sploitus