Executive brief
Neotoma is a data management tool used for organizing relationships and graph data. A security flaw in its query system allows one registered user to view data belonging to another user if they know specific record identifiers. While this does not allow unauthorized users to change or delete data, it creates a privacy risk where private information could be exposed to other account holders on the same system.
Technical details
The `/list_relationships` and `/retrieve_graph_neighborhood` endpoints in Neotoma v0.13.0 fail to enforce proper data scoping. While the application correctly identifies the authenticated user via `getAuthenticatedUserId`, it fails to include the resulting user ID as a filter in the underlying Supabase database queries. An attacker with a valid account and knowledge of a target's entity ID (approximately 96 bits of entropy) can retrieve relationship edges and graph neighborhood data. The vulnerability is caused by missing `.eq("user_id", userId)` filters and improper use of string interpolation in `.or()` queries. The issue is resolved in version 0.14.0.
Affected products
- markmhendrickson neotoma >= 0.13.0, < 0.14.0
Timeline
- 2026-05-22: disclosed
- 2026-06-25: advisory
References
- https://github.com/markmhendrickson/neotoma/security/advisories/GHSA-wrr4-782v-jhwh
- https://github.com/markmhendrickson/neotoma/issues/365
- https://github.com/markmhendrickson/neotoma/issues/366
- https://github.com/markmhendrickson/neotoma/issues/372
- https://api.github.com/repos/markmhendrickson/neotoma/security-advisories/GHSA-wrr4-782v-jhwh