CVE-2026-45829: exploitation status and patch state

CVE-2026-45829 · EPSS 12%

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/{tenant}/databases/{db}/collections endpoint.

Is CVE-2026-45829 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

No patch identifier recorded here yet.

What PlainSec published about CVE-2026-45829

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-11.