An unpatched vulnerability in ChromaDB could be exploited without authentication for remote code execution and server takeover.

An unpatched vulnerability in ChromaDB could be exploited without authentication for remote code execution and server takeover.

A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.