MEDIUM 6.9 NVD
CVE-2026-90601
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. T
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
References
- https://github.com/getzep/graphiti/
- https://github.com/getzep/graphiti/issues/1716
- https://github.com/getzep/graphiti/pull/1739
- https://vuldb.com/cve/CVE-2026-90601
- https://vuldb.com/submit/913951
This medium severity vulnerability with a CVSS score of 6.9 was published on 2026-09-13 via NVD.
vulnfeed aggregates 10822 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.