0.21.5
6 months ago
10 days ago
Known vulnerabilities in the neotoma package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
neotoma is a MCP server for structured personal data memory with unified source ingestion Affected versions of this package are vulnerable to Missing Authentication for Critical Function via the authentication middleware. An attacker can gain unauthorized access to sensitive data and functionality by sending requests through a reverse proxy or same-host tunnel that forwards traffic to the Node process over loopback, causing the application to treat unauthenticated public requests as local. This is only exploitable if the deployment is public and configured behind a reverse proxy or tunnel that forwards requests to the application over a loopback interface. How to fix Missing Authentication for Critical Function? Upgrade | >=0.6.0 <0.11.1 |