graphiti-core
Build Real-Time Knowledge Graphs for AI Agents
Activity
- Latest release
- 5d ago
- Total releases
- 194
- Cadence
- ~daily
- Last 12 months
- 45
Reach
- Stars
- 30.9k
Details
- License
- Apache-2.0
- First release
- Aug 27, 2024
| Version | Released | |
|---|---|---|
0.30.2
patch
| ||
0.30.1
minor
| ||
0.29.3
patch
| ||
0.29.2
patch
| ||
0.29.1
patch
| ||
0.29.0
minor
| ||
0.28.2
patch
| ||
0.28.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.28.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.27.2rc1
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.27.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.27.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.27.0rc2
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.27.0rc1
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.26.3
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.26.2
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.26.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.26.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.5
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.4
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.3
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.2
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.25.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.24.3
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.24.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.24.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.23.1
patch
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.23.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.1rc2
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.1rc1
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc5
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc4
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc3
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc2
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc1
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.22.0rc0
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0
minor
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc13
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc12
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc11
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc10
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc9
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc8
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.21.0rc7
pre
1 CVE
CVE-2026-32247
PYSEC-2026-2504
GHSA-gg5m-55jj-8m5g
Jul 13, 2026
Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
SummaryGraphiti versions before In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels. This issue was mitigated in Affected Versions
Fixed Version
Affected Components
Technical DetailsBefore The vulnerable logic was effectively:
The same pattern was also used in edge-search filter construction. In MCP deployments, ImpactSuccessful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
Additional Note on
| ||
0.30.0rc5
pre
| ||
0.30.0rc4
pre
| ||
0.30.0rc3
pre
| ||
0.30.0rc2
pre
|