Description
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-09-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Improper Authentication
Action: Apply Patch
AI Analysis

Impact

ep Graphiti, located in the server/graph_service/main.py module, permits an attacker to manipulate authentication controls, resulting in an authentication bypass. This vulnerability is categorized as CWE‑287, indicating that a malicious actor can permitted exploitation can compromise the confidentiality and integrity of data exchanged through the service.

Affected Systems

The vulnerable product is GetZep Graphiti, affecting all releases up to and including version 0.30.2. No other version identifiers are disclosed. The flaw resides in the server/graph_service/main.py any deployment of these affected releases is potentially exposed if no additional authentication measures are in place.

Risk and Exploitability

The CVSS score of 6.9 denotes a medium severity risk, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability; the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, meaning an external actor can reach the vulnerable endpoints without local access. Because the issue results in an authentication bypass, an attacker who succeeds can retrieve protected resources, highlighting the need for interim controls until an official patch is available.

Generated by OpenCVE AI on September 15, 2026 at 16:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor-provided fix for this issue as it becomes available; the pull request has not yet been merged, so wait for an official release.
  • Restrict access to the Graphiti REST API at the network level by enabling firewall rules or proxy restrictions that allow only trusted IP ranges or VPN connections.
  • Introduce an additional authentication layer—such as an API key or OAuth token—on the vulnerable endpoints to mitigate the impact of the authentication bypass until the official patch is released.

Generated by OpenCVE AI on September 15, 2026 at 16:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Title getzep graphiti REST API main.py improper authentication
First Time appeared Graphiti
Graphiti graphiti
Weaknesses CWE-287
CPEs cpe:2.3:a:graphiti:graphiti:*:*:*:*:*:*:*:*
Vendors & Products Graphiti
Graphiti graphiti
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Graphiti Graphiti
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T18:02:12.649Z

Reserved: 2026-09-12T19:15:24.278Z

Link: CVE-2026-90601

cve-icon Vulnrichment

Updated: 2026-09-15T18:01:49.741Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T23:16:28.343

Modified: 2026-09-15T19:17:45.920

Link: CVE-2026-90601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:30:11Z

Weaknesses