Max-severity flaw in ChromaDB for AI apps allows server hijacking
…The authentication check is only performed after that step, bypassing security. “The authentication is not missing, [it’s] just in the wrong place,” explains HiddenLayer . “By the time it fires, the model…