CVE-2026-45577
MEDIUMNeotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
Title source: cnaDescription
Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/markmhendrickson/neotoma/security/advisories/GHSA-5cvp-p7p4-mcx9
X_Refsource_Misc x_refsource_misc
https://github.com/markmhendrickson/neotoma/releases/tag/v0.11.1
Scores
CVSS v4
6.9
EPSS
0.0025
EPSS Percentile
15.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-288
CWE-306
Status
published
Products (2)
markmhendrickson/neotoma
>= 0.6.0, < 0.11.1
npm/neotoma
0.6.0 - 0.11.1npm
Published
May 29, 2026
Tracked Since
May 29, 2026