Max-severity flaw in ChromaDB for AI apps allows server hijacking
Max-severity flaw in ChromaDB for AI apps allows server hijacking
Tue May 19 2026
Open Source
Vulnerability
www.bleepingcomputer.com
A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers. [...]