CVE-2026-45577

Source
https://cve.org/CVERecord?id=CVE-2026-45577
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45577.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-45577
Aliases
Published
2026-05-29T16:53:32.982Z
Modified
2026-08-12T03:51:08.738719107Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
Details

Neotoma provides versioned records that persist across agent runs. From 0.6.0 to before 0.11.1, Neotoma can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present. In affected deployments, the REST auth middleware can resolve unauthenticated requests as the local development user, making the hosted Inspector and related API surface reachable without credentials. This vulnerability is fixed in 0.11.1.

Database specific
{
    "cwe_ids": [
        "CWE-288",
        "CWE-306"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/45xxx/CVE-2026-45577.json"
}
References

Affected packages

Git / github.com/markmhendrickson/neotoma

Affected ranges

Type
GIT
Repo
https://github.com/markmhendrickson/neotoma
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0.6.0"
        },
        {
            "fixed": "0.11.1"
        },
        {
            "introduced": "0"
        }
    ]
}

Affected versions

v0.*
v0.10.0
v0.10.1
v0.11.0
v0.6.0
v0.7.0
v0.7.1
v0.8.0
v0.9.0
v0.9.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-45577.json"