Vulnerability Description
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/getzep/graphiti/
- https://github.com/getzep/graphiti/issues/1716
- https://github.com/getzep/graphiti/pull/1739
- https://vuldb.com/cve/CVE-2026-90601
- https://vuldb.com/submit/913951
- https://vuldb.com/vuln/403183
- https://vuldb.com/vuln/403183/cti
- https://github.com/getzep/graphiti/issues/1716
FAQ
What is CVE-2026-90601?
CVE-2026-90601 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper auth...
How severe is CVE-2026-90601?
CVE-2026-90601 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-90601?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.