FixVibe

// نشط / تسليط الضوء

ChromaDB Python Backend RCE Advisory

A self-hosted ChromaDB on the Python backend can run attacker code before login.

What it is

ChromaDB is a popular vector database for retrieval-augmented AI features, and small teams often run it themselves next to their app. CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend, not the default Rust frontend, so the risk depends on which server you deployed as well as which release.

How it happens

CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend: attacker-controlled embedding-function configuration is processed before authorization, which can lead to code execution on the server. The default Rust frontend is not affected.

What an attacker gets

If the identified Python backend is reachable from an untrusted network, the advisory describes pre-authentication code execution with the server process privileges. That puts the vectors, the documents behind them, and every credential the process can read, such as model-provider API keys, within an attacker's reach.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Move the service to Chroma's supported Rust-based deployment path or a vendor-confirmed patched Python release. Block untrusted access before it reaches ChromaDB, restrict unnecessary outbound model-registry access, and review ChromaDB and host logs, environment variables, mounted credentials, and process activity if the Python backend was exposed.

// شغّله على تطبيقك

واصل الإطلاق بينما يراقب FixVibe المخاطر.

Verify you own the domain, then run active checks alongside the passive ones.

الفحوصات النشطة
138
اختبار في هذه الفئة
وحدة
58
فحص الفحوصات النشطة مخصص
verified domains
130+
active checks after verification
Verify your domain →

// فحوصات حديثة · إصلاحات عملية · أطلق بثقة

ChromaDB Python Backend RCE Advisory: what it is and how to fix it · FixVibe