CVE 6.9 MEDIUM

Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass_CVE-2026-45577

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.

Basic Information

ID CVE-2026-45577
Source GitHub_M
Published May 29, 2026 at 16:53

Affected Product

Vendor markmhendrickson
Product neotoma
Version >= 0.6.0, < 0.11.1
Affected Versions markmhendrickson neotoma >= 0.6.0, < 0.11.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.