neotoma@0.13.0

MCP server for structured personal data memory with unified source ingestion

  • latest version

    0.21.5

  • latest non vulnerable version

  • first published

    6 months ago

  • latest version published

    10 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the neotoma package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Insertion of Sensitive Information Into Sent Data

    neotoma is a MCP server for structured personal data memory with unified source ingestion

    Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data in the /list_relationships and /retrieve_graph_neighborhood endpoints due to missing user ID filtering in Supabase queries. An attacker can access relationship and graph neighborhood data belonging to other users by providing a valid authentication token and a known entity ID associated with another user. This is only exploitable if the attacker has a legitimate account on the same instance and knows a valid entity ID belonging to another user.

    How to fix Insertion of Sensitive Information Into Sent Data?

    Upgrade neotoma to version 0.14.0 or higher.

    >=0.13.0 <0.14.0