CVE-2026-33286Disclosure(graphiti / graphiti)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch graphiti graphiti systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. Any application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The `Graphiti::Util::ValidationResponse#all_valid?` method recursively calls `model.send(name)` using relationship names taken directly from user-supplied JSONAPI payloads, without validating them against the resource's configured sideloads. This allows an attacker to potentially run any public method on a given model instance, on the instance class or associated instances or classes, including destructive operations. This is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. Some workarounds are available. Ensure Graphiti write endpoints (create/update) are not accessible to untrusted users and/or apply strong authentication and authorization checks before any write operation is processed, for example use Rails strong parameters to ensure only valid parameters are processed.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • graphiti

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-24); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
graphiti

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-03-22: 1Mentions · 2026-03-24: 5Mentions · 2026-03-25: 1Mentions · 2026-04-07: 1Patch / Workaround · 2026-03-24: 2Technical Details · 2026-03-22: 1Technical Details · 2026-03-24: 5Technical Details · 2026-03-25: 103-2203-2403-2504-07
Signal classification3 categories
Disclosure
562.5%
General
225.0%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-221
Disclosure1
2026-03-245
Disclosure4Patch1
2026-03-251
General1
2026-04-071
General1
Full discourse8 posts
  • Firmis Labs@FirmisLabs
    General

    CVE-2026-33286 · NIST 9.1/10 https://nvd.nist.gov/vuln/detail/CVE-2026-33286

    Post summary

    The text merely cites a CVE identifier with its NIST CVSS score and a link to the NVD entry, providing no further technical, exploit, or mitigation details.

    1000027
    1 followersView on X
  • RUBYLAND@rubylandnews
    Disclosure

    RubySec ➜ CVE-2026-33286 (graphiti): Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names https://rubysec.com/advisories/CVE-2026-33286/

    Post summary

    RubySec has disclosed CVE-2026-33286 for Graphiti, detailing an arbitrary method execution flaw tied to unvalidated relationship names; no PoC, exploit, or patch information is provided.

    0001090
    2.7K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-33286 📊 Severity: 9.1 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-33286 #CVE-2026-33286 #CVE #Critical  #CyberSecurity #InfoSec https://t.co/Es5meW9j5t

    Post summary

    The tweet offers a brief CVE alert with a severity score but lacks details about exploitation, mitigations, or a PoC.

    0000041
    114 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33286 Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vu… https://www.cve.org/CVERecord?id=CVE-2026-33286

    Post summary

    The text announces that Graphiti versions earlier than 1.10.2 have an arbitrary method execution flaw, and upgrading to 1.10.2 or later mitigates the issue.

    00000139
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33286 - Critical Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affe... https://www.thehackerwire.com/vulnerability/CVE-2026-33286/ https://t.co/rKt6Z17qCr

    Post summary

    The post announces CVE-2026-33286 as a critical arbitrary method execution flaw in Graphiti before v1.10.2, with a link to a detailed article but no PoC or active exploitation evidence.

    0000040
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33286: CRITICAL] Vulnerability in Graphiti versions < 1.10.2 allows arbitrary method execution via JSONAPI payloads. Patched in v1.10.2. Upgrade ASAP or implement security measures.#cve,CVE-2026-33286,#cybersecurity https://cvefind.com/CVE-2026-33286

    Post summary

    The post discloses a critical Graphiti vulnerability that allows arbitrary method execution, notes a patch in version 1.10.2, and urges immediate upgrade or mitigation.

    0000057
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33286: Graphiti Affected by Arbitrary M... Unauthenticated RCE via `model.send(name)` with user-controlled relationship names - every Rails API using Graphiti wri... https://zerodaysignal.com/vulnerability/CVE-2026-33286 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑33286, describing an unauthenticated RCE in Graphiti’s Rails API, but provides neither a PoC nor evidence of active exploitation.

    0000051
    165 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical arbitrary method execution vulnerability (CVE-2026-33286) impacts `Graphiti` due to unvalidated relationship names. Evaluate API input validation for `Graphiti` applications. #Graphiti #CVE #infosec https://www.pulsepatch.io/posts/cve-2026-33286-graphiti-arbitrary-method-execution

    Post summary

    The post announces a new arbitrary method execution flaw in Graphiti due to unvalidated relationship names, urging users to review API input validation.

    0000030
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgraphitigraphiti-ruby-

Explore more