What it is
ChromaDB is a popular vector database for retrieval-augmented AI features, and small teams often run it themselves next to their app. CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend, not the default Rust frontend, so the risk depends on which server you deployed as well as which release.
How it happens
CVE-2026-45829 affects ChromaDB's optional Python FastAPI backend: attacker-controlled embedding-function configuration is processed before authorization, which can lead to code execution on the server. The default Rust frontend is not affected.
What an attacker gets
If the identified Python backend is reachable from an untrusted network, the advisory describes pre-authentication code execution with the server process privileges. That puts the vectors, the documents behind them, and every credential the process can read, such as model-provider API keys, within an attacker's reach.
// what fixvibe reports
What FixVibe reports
Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Move the service to Chroma's supported Rust-based deployment path or a vendor-confirmed patched Python release. Block untrusted access before it reaches ChromaDB, restrict unnecessary outbound model-registry access, and review ChromaDB and host logs, environment variables, mounted credentials, and process activity if the Python backend was exposed.
