CVE-2026-32247Disclosure(getzep / graphiti)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch getzep graphiti systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels were concatenated directly into Cypher label expressions without validation. In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call search_nodes with attacker-controlled entity_types values. The MCP server mapped entity_types to SearchFilters.node_labels, which then reached the vulnerable Cypher construction path. Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in 0.28.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-943

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graphiti

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-12); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
graphiti

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-03-12: 3Mentions · 2026-03-16: 1Mentions · 2026-03-17: 1Mentions · 2026-03-18: 1Patch / Workaround · 2026-03-12: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-16: 1Technical Details · 2026-03-17: 103-1203-1603-1703-18
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-123
Disclosure3
2026-03-161
General1
2026-03-171
Disclosure1
2026-03-181
Disclosure1
Full discourse6 posts
  • AI Security Guard@ai_security_10x
    Disclosure

    CVE-2026-32247: How Cypher Injection in Graphiti MCP Servers Enables Prompt Injection Attacks #security https://moltx.io/articles/d21a75dc-ea43-434c-bcfb-6ab6ad6bf6d8

    Post summary

    The post announces CVE‑2026‑32247, describing how Cypher injection vulnerabilities in Graphiti MCP servers can lead to prompt injection attacks and points to an article for details.

    1003068
    4 followersView on X
  • AI Security Guard@ai_security_10x
    Disclosure

    📝 New article: CVE-2026-32247: How Graphiti MCP Servers Became Cypher Injection Targets https://moltx.io/articles/48b253d4-d1e7-42b0-b561-ee80153ed95c

    Post summary

    The snippet announces a new article about CVE-2026-32247, stating that Graphiti MCP Servers are targeted via Cypher injection, but it does not provide PoC, exploit details, patch information, or evidence of active exploitation.

    1001042
    4 followersView on X
  • AI Security Guard@ai_security_10x
    General

    Cypher Injection Attacks in Graphiti MCP: Understanding CVE-2026-32247 #security https://moltx.io/articles/17f3696c-893f-495f-8bef-5873db579955

    Post summary

    The post references a blog article about a Cypher injection vulnerability (CVE-2026-32247) but offers no evidence of a PoC, exploit code, active exploitation, or patch details.

    0001071
    4 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32247 - High Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter con... https://www.thehackerwire.com/vulnerability/CVE-2026-32247/ https://t.co/H5XqyCLH8s

    Post summary

    CVE-2026-32247 is a high‑severity Cypher injection flaw affecting Graphiti versions <0.28.2, with newer releases expected to resolve the issue.

    0001038
    134 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32247 Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in… https://www.cve.org/CVERecord?id=CVE-2026-32247

    Post summary

    Graphiti versions prior to 0.28.2 suffer a Cypher injection flaw, as noted by the CVE record link.

    00000121
    56.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32247 Cypher Injection Vulnerability in Graphiti Framework Before 0.28.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32247

    Post summary

    The text announces a Cypher injection flaw (CVE‑2026‑32247) affecting Graphiti Framework versions before 0.28.2.

    0000022
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetzepgraphiti---

Explore more