6.9
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Description
Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.
Basic Information
ID
CVE-2026-45577
Source
GitHub_M
Published
May 29, 2026 at 16:53
Affected Product
Vendor
markmhendrickson
Product
neotoma
Version
>= 0.6.0, < 0.11.1
Affected Versions
markmhendrickson neotoma >= 0.6.0, < 0.11.1