---
schema: 1
kind: vulnerability
title: "CVE-2026-45829 — ChromaDB Python FastAPI server: pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; still unpatched in v1.5.9)"
headline: "CVE-2026-45829 — ChromaDB Python FastAPI server: pre-auth RCE via embedding-function model loading before auth check (CVSS 4.0 = 10.0; still unpatched in"
summary: "HiddenLayer / Hadrian researchers disclosed CVE-2026-45829, a CVSS 4.0 = 10.0 pre-authentication RCE in ChromaDB's Python FastAPI server (affected from v1.0.0) (Hadrian Security, 2026-05-19; BleepingComputer, 2026-05-19)."
discovered_at: "2026-05-21T05:00:04Z"
event_date: 2026-05-19
run_id: 2026-05-21-77cdc4cd
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - pre-auth
  - no-patch
  - poc-public
  - ai-abuse
regions:
  - global
sectors:
  - technology
  - education
entities: []
cves:
  - id: CVE-2026-45829
    cvss: "10.0"
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - poc-public
      - no-patch
sources:
  - url: "https://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are"
    publisher: Hadrian Security
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/"
    publisher: BleepingComputer
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Disable the ChromaDB Python FastAPI server or block external access** — CVE-2026-45829 has a public PoC, v1.5.9 is unpatched, and the Python server is the affected component (the Rust server is not). Migrate to the Rust server (`chroma run`) or front the API with network-layer access controls; ensure no ChromaDB deployment is internet-exposed (."
migrated_from: briefs/2026-05-21.md
---

HiddenLayer / Hadrian researchers disclosed CVE-2026-45829, a CVSS 4.0 = 10.0 pre-authentication RCE in ChromaDB's Python FastAPI server (affected from v1.0.0) ([Hadrian Security, 2026-05-19](https://hadrian.io/blog/cve-2026-45829----chromadb-python-server-hands-you-rce-before-it-asks-who-you-are); [BleepingComputer, 2026-05-19](https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/)). The vulnerable endpoint is `POST /api/v2/tenants/{tenant}/databases/{db}/collections`: when the request body sets `trust_remote_code: true` with an attacker-controlled HuggingFace model identifier (or a local path), the server fetches and executes the attacker-supplied Python code *before* the auth check fires, then politely returns `403 Forbidden` after the code has run. The flaw exists only in the Python FastAPI server (`chromadb[server]` pip package) — the default Rust server (`chroma run`) does not traverse this code path. Per [BleepingComputer's reporting of Shodan queries](https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/), approximately 73 % of internet-exposed ChromaDB instances are running a vulnerable version of the software. **As of disclosure, ChromaDB v1.5.9 (latest) is unpatched.** Mitigations: disable the Python FastAPI server and migrate to the Rust server; alternatively, block network-level access to the ChromaDB API (it should never be internet-exposed in the first place); if internal, set `trust_remote_code: false` server-wide via config. Detection concept — unexpected outbound network connections from ChromaDB Python server processes; child processes spawned by `uvicorn` / `gunicorn` workers with non-default lineage; access logs showing `POST /api/v2/.../collections` bodies referencing HuggingFace repository slugs with attacker-controlled patterns. `T1190` Exploit Public-Facing Application; the impact maps to `T1059.006` Python execution under the server context.
