Executive brief
Graphiti is an open-source knowledge graph platform used by AI agents to store and retrieve contextual information. The graph-service component exposes all REST API endpoints without any authentication controls, allowing unauthenticated remote attackers to delete entire graph databases, access other tenants' data, and corrupt graph records. This results in complete loss of data confidentiality, integrity, and availability for all users.
Technical details
The vulnerability is a missing authentication (CWE-306) in the FastAPI application's graph-service component. The root cause is the absence of authentication middleware in server/graph_service/main.py—all endpoints in routers/ingest.py and routers/retrieve.py are registered without auth checks. An unauthenticated remote attacker can call POST /clear to delete the entire graph database via raw Cypher (MATCH (n) DETACH DELETE n), DELETE /group/{group_id} to remove arbitrary tenants' data, POST /search with victim group_ids to leak facts across tenants, and POST /messages with attacker-controlled uuid to overwrite other tenants' episodes. The attack requires only network access to the default port 8000 and no credentials. A fix PR is pending acceptance.
Affected products
- getzep Graphiti up to 0.30.2
Timeline
- 2026-09-13: disclosed
- other: Fix PR awaits acceptance