Authentication Sequencing Flaw in ChromaDB Python Server Enables Unauthenticated RCE via Hugging Face Model Loading
CVE-2026-45829 in ChromaDB’s Python FastAPI server allows unauthenticated remote code execution by executing malicious models from Hugging Face before authentication verification, affecting an estimated 73% of exposed instances and posing significant risk to agentic AI deployments reliant on dynamic model loading. Read more