Improper Authentication in Getzep Graphiti REST API
CVE-2026-90601

6.9MEDIUM

Key Information:

Vendor

Getzep

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90601?

A vulnerability has been identified in the Getzep Graphiti REST API, specifically in an unknown function within the server/graph_service/main.py file. This flaw allows for improper authentication, enabling potential attackers to manipulate the API remotely. Currently, a pull request to address this issue is pending acceptance, highlighting the importance of prompt attention to ensure user security and maintain integrity in the API functionality.

Affected Version(s)

graphiti 0.30.0

graphiti 0.30.1

graphiti 0.30.2

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Default01 (VulDB User)
VulDB CNA Team
.