A new, particularly serious vulnerability in ChromaDB (an open-source vector database widely used in AI applications) allows an attacker to perform remote code execution without any authentication. The vulnerability is documented as CVE-2026-45829 and has been nicknamed “ChromaToast” by researchers at HiddenLayer.

The most concerning aspect isn’t just the RCE. It’s how it’s done: according to the research, ChromaDB’s Python/FastAPI server can “load” and execute client-controlled embedding function settings before the access check. In simple terms, the application can run code that it “brings” from outside, and then see that the user didn’t have permission.
What exactly is the attacker exploiting?
ChromaDB, as a vector DB, requires embeddings to function. To be flexible, it allows the client to specify settings for the embedding function (e.g. which model to use). As HiddenLayer describes, in the collection creation endpoint in question, the server accepts parameters that include a reference to a model repository in Hugging Face.
See also: Hugging Face: Fake OpenAI Privacy Filter Repo with 244K downloads
This is where the crucial parameter comes in: trust_remote_code: true. This is a flag that exists in the Hugging Face ecosystem and when enabled, it allows Python code that accompanies the model repo to be downloaded and executed. It is useful for custom architectures, but at the same time it means that a model can be “executable code”.
According to HiddenLayer, with a crafted request, the server:
- accepts request without credentials,
- downloads the model shown by the attacker,
- executes the model code (due to trust_remote_code) and
- then it runs the authentication check and rejects the request.
From the API client's perspective, the request may appear to have "failed" (e.g. 500). However, from the attacker's perspective, the code has already run and there is a shell on the server.

Who is affected by the ChromaDB vulnerability?
HiddenLayer reports that the vulnerability exists from version 1.0.0 to 1.5.8 (at the time of publication). In NVD, the description highlights that the exploit is related to the endpoint /api/v2/tenants/{tenant}/databases/{db}/collections and sending a malicious model reference with trust_remote_code.
In practice, the risk concerns organizations/teams that:
- running the Python/FastAPI version of the server,
- have the service network accessible (internet-exposed or "open" to large internal networks),
- they use embedding functions/settings that are loaded dynamically.
See also: Critical bug leaves Hugging Face's LeRobot exposed
What can an attacker do after the takeover?
With RCE in the same server process, the attacker can gain access to:
- environment variables,
- API keys,
- mounted secrets (e.g. Kubernetes secrets),
- files on disk,
- and of course the database data/collections.
In real AI infrastructures, this often means “keys” to clouds, LLM APIs, pipelines, and data warehouses.

Practical steps/mitigations (what admins should do)
Until there is an official patch, HiddenLayer suggests the following:
- Avoid internet exposure: close access to the ChromaDB port from untrusted networks.
- Put firewall rules / security groups / allowlists.
- Network segmentation: even internally, allow access only from applications that really need it.
- Prefer “Rust-based deployment path” (where possible): according to HiddenLayer, the Rust frontend/path is not affected.
- Monitoring: record/monitor requests to the collection creation endpoint and unexpected calls to Hugging Face from the server.
- Secrets hygiene: if a breach is suspected, consider that API keys/credentials may have been leaked and proceed with rotation.
See also: Abuse of Hugging Face to distribute Android malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
What does it mean for Greece/businesses/admins/users?
ChromaDB is not a "consumer app" — it's infrastructure. However, in Greece, more and more groups (startups, integrators, data/AI departments in banks, telecoms, e-commerce, even public) are setting up RAG systems and semantic search on vector databases.
If such a service is exposed or over-accessible internally, the attack can become the “first step” for:
- theft of cloud credentials (AWS/Azure/GCP),
- access to embedded customer/document data,
- pivot to other systems (CI/CD, Kubernetes, storage),
- and finally ransomware or data extortion.
