CVE-2026-90601: getzep graphiti REST API main.py improper authentication
Published Sep 13, 2026
·Updated
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graphservice/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Affected Software
1 affected component
getzep/graphiti<=0.30.2
Event History
Sep 13, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be prioritized for review?
Deployments of getzep graphiti versions up to 0.30.2 should be reviewed, particularly where the REST API is reachable remotely.
2
Does an attacker need credentials or user interaction to exploit this issue?
The available severity vector indicates no privileges and no user interaction are required. The attack vector is network-based and the attack complexity is low.
3
Is a vendor fix available?
A pull request intended to fix the issue exists, but it awaits acceptance. No accepted fixed release is identified in the available information.