{"id":"CVE-2026-45829","title":"A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…","summary":"A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_c…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-94","CWE-502"],"published":"2026-05-18","updated":"2026-07-15","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-45829","references":[{"url":"https://github.com/chroma-core/chroma/issues/6717","label":"6f8de1f0-f67e-45a6-b68f-98777fdb759c"},{"url":"https://www.hiddenlayer.com/research/chromatoast-served-pre-auth","label":"6f8de1f0-f67e-45a6-b68f-98777fdb759c"},{"url":"https://access.redhat.com/security/cve/CVE-2026-45829","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479623","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45829.json","label":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c"},{"url":"https://www.hiddenlayer.com/research/chromatoast-served-pre-auth","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.12387,"epssPercentile":0.96075,"ingestedAt":"2026-07-16T02:48:54.924Z","exploits":{"github":2,"githubRepos":["https://github.com/fevar54/FULL-ANALYSIS---CVE-2026-45829-ChromaDB-","https://github.com/0xBlackash/CVE-2026-45829"],"checkedAt":"2026-09-21T15:29:08.104Z"},"exploitAvailable":true,"slug":"CVE-2026-45829","body":"## Overview\n\nA pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":69,"depthScoreParts":{"impact":55,"likelihood":2.5,"exploitation":12,"ransomware":0},"changes":[{"seq":5244,"id":"CVE-2026-45829","ts":1788887256321,"field":"exploit_available","old":"false","new":"true"},{"seq":4127,"id":"CVE-2026-45829","ts":1788886372724,"field":"exploit_available","old":"true","new":"false"},{"seq":2900,"id":"CVE-2026-45829","ts":1788883038647,"field":"exploit_available","old":"false","new":"true"},{"seq":1929,"id":"CVE-2026-45829","ts":1788882441669,"field":"exploit_available","old":"true","new":"false"},{"seq":1018,"id":"CVE-2026-45829","ts":1788881876491,"field":"exploit_available","old":"false","new":"true"}]}