HIGH
CVE-2026-90601
CVSS
7.3
Description
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The attack can be launched remotely. The pull request to fix this issue awaits acceptance.
Weakness (CWE)
CWE-287
Improper Authentication
EPSS Score
0.41%
Probability of exploitation in next 30 days
34.9th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.