Your AI Has a Memory. Anyone Can Read It. Anyone Can Poison It.

ChromaDB ships with no authentication. This episode breaks the RAG stack built in 3.4A -- exfiltrating every internal document, poisoning the knowledge base to phish users via the AI, jamming retrieval with blocker documents, and deleting the entire collection. All from the network, with curl and five lines of Python.

April 2, 2026 · 28 min · Oob Skulden™