In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade neotoma to version 0.14.0 or higher.
neotoma is a MCP server for structured personal data memory with unified source ingestion
Affected versions of this package are vulnerable to Insertion of Sensitive Information Into Sent Data in the /list_relationships and /retrieve_graph_neighborhood endpoints due to missing user ID filtering in Supabase queries. An attacker can access relationship and graph neighborhood data belonging to other users by providing a valid authentication token and a known entity ID associated with another user. This is only exploitable if the attacker has a legitimate account on the same instance and knows a valid entity ID belonging to another user.