Junglewise Threat Intelligence

neotoma tenant isolation gap in relationship query endpoints

Severity: medium · CVSS 4 · Published 2026-06-25

Technologies: Neotoma. Vendors: npm.

Executive brief

Neotoma is a data management library used for querying and managing relationships between entities. An authenticated user can view relationship and graph data belonging to other users on the same instance by knowing their entity IDs, bypassing per-user data isolation controls. This allows unauthorized cross-user data exposure in multi-user deployments.

Technical details

The vulnerability is a missing data isolation filter (CWE-201: Exposure of Sensitive Information to an Unauthorized Actor) in the /list_relationships and /retrieve_graph_neighborhood endpoints. Both endpoints call getAuthenticatedUserId to verify a valid session exists, but fail to apply an .eq("user_id", userId) filter to Supabase queries, causing them to return rows from all users rather than just the authenticated caller's data. The attack requires an authenticated account on the same instance plus knowledge of another user's entity ID (approximately 96 bits of entropy, making brute-force impractical). No write capability is exposed. Fix is available in version 0.14.0, which adds proper user ID scoping to both query handlers.

Affected products

  • neotoma neotoma 0.13.0

Timeline

  • 2026-06-25: disclosed

References

Related threats