graphiti
Stylish Graph APIs, built on JSON:API
Activity
- Latest release
- 1w ago
- Total releases
- 186
- Cadence
- ~daily
- Last 12 months
- 34
Reach
- Downloads
- 1.7M
- Stars
- 1.1k
Details
- License
- MIT
- First release
- Jul 31, 2018
| Version | Released | |
|---|---|---|
2.1.1
patch
|
2.1.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.1.0
minor
|
2.1.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.2
patch
|
2.0.2
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.13.5
patch
|
1.13.5
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.1
patch
|
2.0.1
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0
major
|
2.0.0
major
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.13
pre
|
2.0.0.beta.13
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.12
pre
|
2.0.0.beta.12
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.11
pre
|
2.0.0.beta.11
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.10
pre
|
2.0.0.beta.10
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.9
pre
|
2.0.0.beta.9
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
1.13.4
patch
|
1.13.4
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.8
pre
|
2.0.0.beta.8
pre
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
2.0.0.beta.7
pre
|
2.0.0.beta.7
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.6
pre
|
2.0.0.beta.6
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.13.3
patch
|
1.13.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.5
pre
|
2.0.0.beta.5
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.4
pre
|
2.0.0.beta.4
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.13.2
patch
|
1.13.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.13.1
patch
|
1.13.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.3
pre
|
2.0.0.beta.3
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.13.0
minor
|
1.13.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.2
pre
|
2.0.0.beta.2
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
2.0.0.beta.1
pre
|
2.0.0.beta.1
pre
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.12.0
minor
|
1.12.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.12.2
patch
|
1.12.2
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.12.1
patch
|
1.12.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.11.1
patch
|
1.11.1
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.10.3
patch
|
1.10.3
patch
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.11.0
minor
|
1.11.0
minor
Dependencies (14)
+ 6 more
Changelog
Compare changes
|
|
1.10.2
patch
|
1.10.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.10.1
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.10.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.10.0
minor
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.10.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.9.0
minor
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.9.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.2
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.8.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.1
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.8.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.8.0
minor
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.8.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.8
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.8
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.9
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.9
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.7
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.7
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.6
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.6
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.5
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.5
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.4
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.3
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.2
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.1
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.7.0
minor
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.7.0
minor
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.6.4
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.6.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.6.3
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.6.3
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
1.6.1
patch
1 CVE
CVE-2026-33286
GHSA-3m5v-4xp5-gjg2
Mar 20, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
SummaryAn arbitrary method execution vulnerability has been found which affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. ImpactAny application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The PatchesThis is patched in Graphiti v1.10.2. Users should upgrade as soon as possible. WorkaroundsIf upgrading to v1.10.2 is not immediately possible, consider one or more of the following mitigations:
Affected versions
1.0.0
1.0.1
1.0.2
1.0.3
1.0.alpha.1
1.0.alpha.10
1.0.alpha.11
1.0.alpha.12
1.0.alpha.14
1.0.alpha.15
1.0.alpha.16
1.0.alpha.17
+ 143 more Show less
1.0.alpha.18
1.0.alpha.19
1.0.alpha.20
1.0.alpha.21
1.0.alpha.22
1.0.alpha.23
1.0.alpha.24
1.0.alpha.25
1.0.alpha.26
1.0.alpha.4
1.0.alpha.5
1.0.alpha.6
1.0.alpha.7
1.0.alpha.8
1.0.alpha.9
1.0.beta.10
1.0.beta.11
1.0.beta.12
1.0.beta.13
1.0.beta.14
1.0.beta.15
1.0.beta.16
1.0.beta.17
1.0.beta.18
1.0.beta.19
1.0.beta.2
1.0.beta.20
1.0.beta.21
1.0.beta.22
1.0.beta.23
1.0.beta.3
1.0.beta.4
1.0.beta.5
1.0.beta.6
1.0.beta.7
1.0.beta.8
1.0.beta.9
1.0.rc.1
1.0.rc.10
1.0.rc.11
1.0.rc.12
1.0.rc.14
1.0.rc.15
1.0.rc.16
1.0.rc.17
1.0.rc.18
1.0.rc.19
1.0.rc.2
1.0.rc.21
1.0.rc.22
1.0.rc.23
1.0.rc.24
1.0.rc.25
1.0.rc.26
1.0.rc.27
1.0.rc.28
1.0.rc.3
1.0.rc.4
1.0.rc.5
1.0.rc.6
1.0.rc.7
1.0.rc.8
1.0.rc.9
1.1.0
1.1.1
1.10.0
1.10.1
1.2.0
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.17
1.2.18
1.2.19
1.2.2
1.2.20
1.2.21
1.2.25
1.2.26
1.2.27
1.2.28
1.2.29
1.2.3
1.2.30
1.2.31
1.2.32
1.2.33
1.2.34
1.2.35
1.2.36
1.2.37
1.2.38
1.2.39
1.2.4
1.2.40
1.2.41
1.2.42
1.2.43
1.2.44
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4
1.3.5
1.3.6
1.3.7
1.3.8
1.3.9
1.4.0
1.5.0
1.5.1
1.5.2
1.5.3
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.7.7
1.7.8
1.7.9
1.8.0
1.8.1
1.8.2
1.9.0
Fixed in
1.10.2
References
Updated Mar 25, 2026 · Source: OSV.dev |
1.6.1
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|