ChromaDB Race Condition Remote Code Execution | MSSP Advisory
Critical
DateMay 21, 2026
📋Executive Summary
ChromaDB versions 1.0.0 through 1.5.8 contain a critical race condition vulnerability (CVE-2026-45829) that allows unauthenticated remote code execution through malicious model configurations loaded from Hugging Face. The flaw bypasses authentication checks because the model execution happens before the auth validation completes. Over 73% of internet-exposed ChromaDB instances run vulnerable versions.
⚠️Why It Matters for MSSPs
Your clients deploying AI applications likely run ChromaDB as their vector database, and this gives attackers direct RCE without authentication. If your own development or testing environments use ChromaDB for AI proof-of-concepts or client demos, you have direct exposure through your infrastructure. Clients expect you to know about critical flaws in their AI stack before they get compromised.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Vulnerability Disclosure
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.