Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-5cvp-p7p4-mcx9 | Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 29 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 29 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1. | |
| Title | Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass | |
| Weaknesses | CWE-288 CWE-306 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-29T19:28:05.378Z
Reserved: 2026-05-12T19:00:14.600Z
Link: CVE-2026-45577
Updated: 2026-05-29T19:27:46.868Z
Status : Received
Published: 2026-05-29T18:17:10.007
Modified: 2026-05-29T18:17:10.007
Link: CVE-2026-45577
No data.
OpenCVE Enrichment
Updated: 2026-05-29T18:30:05Z
Github GHSA