
CVE-2026-33286 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33286
Post summary
The text merely cites a CVE identifier with its NIST CVSS score and a link to the NVD entry, providing no further technical, exploit, or mitigation details.
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. Any application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The `Graphiti::Util::ValidationResponse#all_valid?` method recursively calls `model.send(name)` using relationship names taken directly from user-supplied JSONAPI payloads, without validating them against the resource's configured sideloads. This allows an attacker to potentially run any public method on a given model instance, on the instance class or associated instances or classes, including destructive operations. This is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. Some workarounds are available. Ensure Graphiti write endpoints (create/update) are not accessible to untrusted users and/or apply strong authentication and authorization checks before any write operation is processed, for example use Rails strong parameters to ensure only valid parameters are processed.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-03-22 | 1 | Disclosure1 |
| 2026-03-24 | 5 | Disclosure4Patch1 |
| 2026-03-25 | 1 | General1 |
| 2026-04-07 | 1 | General1 |

CVE-2026-33286 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33286
Post summary
The text merely cites a CVE identifier with its NIST CVSS score and a link to the NVD entry, providing no further technical, exploit, or mitigation details.

RubySec ➜ CVE-2026-33286 (graphiti): Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names https://rubysec.com/advisories/CVE-2026-33286/
Post summary
RubySec has disclosed CVE-2026-33286 for Graphiti, detailing an arbitrary method execution flaw tied to unvalidated relationship names; no PoC, exploit, or patch information is provided.

⚡ New CVE Alert: CVE-2026-33286 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33286 #CVE-2026-33286 #CVE #Critical #CyberSecurity #InfoSec https://t.co/Es5meW9j5t
Post summary
The tweet offers a brief CVE alert with a severity score but lacks details about exploitation, mitigations, or a PoC.

CVE-2026-33286 Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vu… https://www.cve.org/CVERecord?id=CVE-2026-33286
Post summary
The text announces that Graphiti versions earlier than 1.10.2 have an arbitrary method execution flaw, and upgrading to 1.10.2 or later mitigates the issue.

🔴 CVE-2026-33286 - Critical Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affe... https://www.thehackerwire.com/vulnerability/CVE-2026-33286/ https://t.co/rKt6Z17qCr
Post summary
The post announces CVE-2026-33286 as a critical arbitrary method execution flaw in Graphiti before v1.10.2, with a link to a detailed article but no PoC or active exploitation evidence.

[CVE-2026-33286: CRITICAL] Vulnerability in Graphiti versions < 1.10.2 allows arbitrary method execution via JSONAPI payloads. Patched in v1.10.2. Upgrade ASAP or implement security measures.#cve,CVE-2026-33286,#cybersecurity https://cvefind.com/CVE-2026-33286
Post summary
The post discloses a critical Graphiti vulnerability that allows arbitrary method execution, notes a patch in version 1.10.2, and urges immediate upgrade or mitigation.

🚨 CVE-2026-33286: Graphiti Affected by Arbitrary M... Unauthenticated RCE via `model.send(name)` with user-controlled relationship names - every Rails API using Graphiti wri... https://zerodaysignal.com/vulnerability/CVE-2026-33286 #netsec #vulnerability #CVE #sysadmin #zeroday
Post summary
The post announces CVE‑2026‑33286, describing an unauthenticated RCE in Graphiti’s Rails API, but provides neither a PoC nor evidence of active exploitation.

A critical arbitrary method execution vulnerability (CVE-2026-33286) impacts `Graphiti` due to unvalidated relationship names. Evaluate API input validation for `Graphiti` applications. #Graphiti #CVE #infosec https://www.pulsepatch.io/posts/cve-2026-33286-graphiti-arbitrary-method-execution
Post summary
The post announces a new arbitrary method execution flaw in Graphiti due to unvalidated relationship names, urging users to review API input validation.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | graphiti | graphiti | - | ruby | - |