Impact
ep Graphiti, located in the server/graph_service/main.py module, permits an attacker to manipulate authentication controls, resulting in an authentication bypass. This vulnerability is categorized as CWE‑287, indicating that a malicious actor can permitted exploitation can compromise the confidentiality and integrity of data exchanged through the service.
Affected Systems
The vulnerable product is GetZep Graphiti, affecting all releases up to and including version 0.30.2. No other version identifiers are disclosed. The flaw resides in the server/graph_service/main.py any deployment of these affected releases is potentially exposed if no additional authentication measures are in place.
Risk and Exploitability
The CVSS score of 6.9 denotes a medium severity risk, and the EPSS score of < 1% indicates a very low but non‑zero exploitation probability; the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, meaning an external actor can reach the vulnerable endpoints without local access. Because the issue results in an authentication bypass, an attacker who succeeds can retrieve protected resources, highlighting the need for interim controls until an official patch is available.
OpenCVE Enrichment