CVE-2026-90601: Getzep Graphiti

High severity, CVSS 7.3. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Affected products

  • Getzep Graphiti: version 0.30.0 only; version 0.30.1 only; version 0.30.2 only

Published 2026-09-13. Last modified 2026-09-15.