Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.
Metrics
Affected Vendors & Products
References
History
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Markmhendrickson
Markmhendrickson neotoma |
|
| Vendors & Products |
Markmhendrickson
Markmhendrickson neotoma |
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1. | |
| Title | Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass | |
| Weaknesses | CWE-288 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-05-29T16:53:32.982Z
Updated: 2026-05-29T19:28:05.378Z
Reserved: 2026-05-12T19:00:14.600Z
Link: CVE-2026-45577
Updated: 2026-05-29T19:27:46.868Z
Status : Received
Published: 2026-05-29T18:17:10.007
Modified: 2026-05-29T18:17:10.007
Link: CVE-2026-45577
No data.