ChromaDB CVE-2026-45829: Pre-Auth RCE Risk in Python Server
ChromaDB CVE-2026-45829, dubbed ChromaToast, can let an unauthenticated attacker execute code through malicious embedding model loading before authentication checks run.
Before you go
Scan your Windows PC for malware, adware, and unwanted programs with a lightweight cleanup tool trusted in our removal guides.
6-day trial available. Offer opens in the same tab.