Local Authentication Bypass in Neotoma by Mark M. Hendrickson
CVE-2026-45577
6.9MEDIUM
What is CVE-2026-45577?
Neotoma versions from 0.6.0 up to but not including 0.11.1 exhibit a security flaw where public reverse-proxied requests can be misconstrued as local requests, specifically when transmitted through a loopback socket in the absence of a Bearer token. This oversight in the REST authorization middleware can lead to unauthorized access, allowing unauthenticated users to interact with the hosted Inspector and related APIs, thus undermining the intended access controls. The issue is remediated in version 0.11.1.
Affected Version(s)
neotoma >= 0.6.0, < 0.11.1
