Junglewise Threat Intelligence

CVE-2026-45577: Neotoma authentication bypass in REST auth middleware

CVE-2026-45577 · Severity: medium · CVSS 4 · Published 2026-05-29

Technologies: Mark Hendrickson Neotoma. Vendors: npm.

Executive brief

Neotoma is a data management system for human-agent interactions. Versions 0.6.0 through 0.11.0 incorrectly treat reverse-proxied requests as local when they arrive over a loopback socket, allowing attackers to bypass authentication and access the Inspector (administration interface) and API without credentials. Organizations running Neotoma behind a reverse proxy or tunnel without proper authentication barriers face unauthorized access to production data.

Technical details

The vulnerability is an authentication bypass (CWE-288, CWE-306) in Neotoma's REST auth middleware. The root cause is flawed local-request detection that trusts loopback sockets unconditionally, even when the request originated from a public client and was forwarded through a reverse proxy. When a reverse proxy forwards traffic to the Node process over 127.0.0.1 without a Bearer token present, the auth middleware incorrectly classifies the request as local/trusted and resolves it as the local development user. This grants unauthenticated access to the hosted Inspector interface and related API endpoints. Exploitation requires only network access to a Neotoma instance behind a reverse proxy; no authentication or user interaction is needed. The fix, deployed in v0.11.1, implements fail-closed local-request detection that checks the X-Forwarded-For header and rejects loopback-socket trust in production by default unless explicitly enabled via NEOTOMA_TRUST_PROD_LOOPBACK=1 environment variable after verification that only trusted local hops reach the Node process.

Affected products

  • Mark Hendrickson Neotoma 0.6.0 through 0.11.0

Timeline

  • 2026-05-18: disclosed
  • 2026-05-18: patched: Fix released in v0.11.1

References

Related threats