← Founder Notes
Archive

The vector db just got an unauthenticated rce. chromadb's chromatoast flaw, flagged oct 11, lets…

Yethikrishna ROriginal on Threads

the vector db just got an unauthenticated rce. chromadb's chromatoast flaw, flagged oct 11, lets anyone execute code before login by pointing the server at a malicious model repo.

the retrieval layer now needs a firewall.

Context

Verified date: HiddenLayer's ChromaToast Served Pre-Auth and the GitHub advisory are dated May 18, 2026. The flaw is CVE-2026-45829. ChromaDB's Python FastAPI server can instantiate user-controlled embedding function settings before checking access permissions, so an unauthenticated attacker with HTTP API access can trigger remote code execution.

The GitHub advisory lists affected versions from 1.0.0 up to 1.5.9.

How it compares

The pre-authentication code execution matches HiddenLayer, GitHub and NVD, but the disclosure is dated May 18, 2026, not Oct 11. The sources describe user-controlled embedding function settings. That the trigger is pointing the server at a malicious model repo was not seen in the sources read, so unsupported here, not refuted. in the excerpts read. 'The retrieval layer now needs a firewall' is the author's opinion.

Related work

Watch next

  • Check whether an Oct 11 follow-up changed the affected versions.

Sources

  1. HiddenLayer: ChromaToast served pre-authhiddenlayer.com
  2. GitHub Advisory Database: ChromaDB pre-authentication code injection, CVE-2026-45829github.com
  3. NVD: CVE-2026-45829nvd.nist.gov

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 11 October 2026 at 21:34 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-vector-db-just-got-an-unauthenticated-rce-DeXC5FGjKtA" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The vector db just got an unauthenticated rce. chromadb's chromatoast flaw, flagged oct 11, lets…"></iframe>

More notes