CVE-2026-90601 PUBLISHED

getzep graphiti REST API main.py improper authentication

Assigner: VulDB
Reserved: 12.09.2026 Published: 13.09.2026 Updated: 13.09.2026

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 6.9

Product Status

Vendor getzep
Product graphiti
Versions
  • Version 0.30.0 is affected
  • Version 0.30.1 is affected
  • Version 0.30.2 is affected

Credits

  • Default01 (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Improper Authentication CWE