ChromaToast Served Pre-Auth (opens in new tab)
HiddenLayer researchers uncovered CVE-2026-45829, a critical vulnerability in ChromaDB’s Python server that enables unauthenticated remote code execution through malicious HuggingFace model loading.
Read the original article