CVE-2026-45833 is a CWE-94 code-injection vulnerability in ChromaDB Python releases from 0.4.17 through the latest affected release. During collection updates, ChromaDB deserializes embedding-function configuration and instantiates the configured model through the embedding-function build path. An authenticated principal permitted to update a collection can supply an attacker-controlled Hugging Face model repository and enable the model loader's remote-code trust option. Loading the embedding function then executes attacker-supplied model code on the ChromaDB server. Equivalent vulnerable behavior exists in both V1 and V2 collection-update API flows.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This five-file Python repository presents itself as an exploit for CVE-2026-45833 affecting ChromaDB. The visible implementation consists of `main.py`, a single entry point that clears the terminal and then reverses, Base64-decodes, zlib-decompresses, and `exec`s a large opaque Python payload. Consequently, the README-claimed `MaliciousModelGenerator`, reconnaissance, single-collection exploitation, and mass-exploitation behavior cannot be independently verified from readable source. `payload.json` supplies readable request templates: it uses an authenticated PUT to a ChromaDB API v2 collection endpoint to set an embedding model with `trust_remote_code: true`, plus proposed shallow-validation bypass variants and a GET verification request. The intended chain is to publish attacker-controlled code as a remote Hugging Face-style model, point a target collection at it, and obtain execution/exfiltration when the server loads the model. The repository has no identifiable exploit framework dependency. Its heavy runtime obfuscation is a significant analysis and operational-risk indicator, but the visible JSON and documentation are consistent with its claimed configuration-injection/RCE purpose; there is no visible destructive fake-exploit behavior.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A code injection vulnerability in ChromaDB Python project version 0.4.17 or later that can allow an authenticated attacker with UPDATE_COLLECTION permission to execute arbitrary code on the server by supplying a malicious model repository with trust_remote_code enabled.
A remote code execution vulnerability in ChromaDB where an authenticated user with UPDATE_COLLECTION permission can update a collection configuration to load a malicious HuggingFace model with trust_remote_code=true, leading to code execution during model instantiation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.