CVE-2026-90601

Summary

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Affected Software

VendorProductVersion RangeStatus
getzepgraphiti0.30.0affected
getzepgraphiti0.30.1affected
getzepgraphiti0.30.2affected

Weaknesses

  • CWE-287: Improper Authentication

References