CVE-2026-90601

A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.

  • Published Sep 13, 2026
  • CVSS 6.9 medium
  • 0.7% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90601 at the National Vulnerability Database