Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
- Severity:
- Medium
Description
Neotoma versions starting at v0.6.0 can treat public reverse-proxied requests as local when the app receives them over a loopback socket and no Bearer token is present.
Recommendation
Update the neotoma package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.6.0, < 0.11.1
- Patched version(s): 0.11.1
References
Related Issues
- LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header - CVE-2026-39411
- StudioCMS S3 Storage Manager Authorization Bypass via Missing `await` on Async Auth Check - CVE-2026-32101
- Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix - CVE-2026-44489
- Axios: no_proxy bypass via IP alias allows SSRF - CVE-2026-42038
You might also like:
- Tags:
- npm
- neotoma
Anything's wrong? Let us know Last updated on June 09, 2026


