A max-severity vulnerability in the latest Python FastAPI version of the ChromaDB project allows unauthenticated attackers to run arbitrary code on exposed servers.
Researchers who found the bug warn that its Moderate rating understates a threat reaching across LLM gateways, MCP servers ...