Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.
Metrics
Affected Vendors & Products
References
History
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1. | |
| Title | Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass | |
| Weaknesses | CWE-288 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T19:28:05.378Z
Reserved: 2026-05-12T19:00:14.600Z
Link: CVE-2026-45577
Updated: 2026-05-29T19:27:46.868Z
Status : Received
Published: 2026-05-29T18:17:10.007
Modified: 2026-05-29T18:17:10.007
Link: CVE-2026-45577
No data.
OpenCVE Enrichment
Updated: 2026-05-29T18:30:05Z