EXPOSURE Chroma
SEVERITY CRITICAL
PROBE GET :8000/api/v2/heartbeat
Is your Chroma exposed?
Embeddings readable, poisonable, deletable, often agent memory (ASI06); auth is opt-in.
Scan a host you own → Fix card Census
Why it matters
Your Chroma database answers anyone. Every embedding can be read, poisoned, or deleted. Embeddings usually contain document text and may hold agent memory (OWASP ASI06). Chroma runs without auth unless you configure it.
How common is it?
806 Chroma instances are reachable in the Shodan index. Fingerprint match, not a verified zero-auth count · src: Shodan count · `product:"Chroma"` · 2026-08
Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.
Fix it
The full walkthrough lives on the fix card, kept current in one place: