Database/AI/ML frameworks & serving
ChromaDB: Pre-authentication code injection
CVE-2026-45829AI/ML frameworks & servingcurated
Impact
Pre-authentication code injection → arbitrary code execution
Who can reach it
Unauthenticated network to the Chroma server
What to do
Upgrade. Maximum severity, no auth required — any tenant-reachable Chroma is fully compromised
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.