CVE Explorer
CVE-2026-33286
Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. Any application exposing Graphiti write endpoints (create/update/delete) to untrusted users is a
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"graphiti","vendor":"graphiti-api","versions":[{"status":"affected","version":"< 1.10.2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-913","description":"CWE-913: Improper Control of Dynamically-Managed Code Resources","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/graphiti-api/graphiti/commit/ddb5ad2b69330774bd1a47935ed89a9fe4396a54","tags":["x_refsource_MISC"],"url":"https://github.com/graphiti-api/graphiti/commit/ddb5ad2b69330774bd1a47935ed89a9fe4396a54"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/references/1
{"name":"https://github.com/graphiti-api/graphiti/releases/tag/v1.10.2","tags":["x_refsource_MISC"],"url":"https://github.com/graphiti-api/graphiti/releases/tag/v1.10.2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/references/2
{"name":"https://github.com/graphiti-api/graphiti/security/advisories/GHSA-3m5v-4xp5-gjg2","tags":["x_refsource_CONFIRM"],"url":"https://github.com/graphiti-api/graphiti/security/advisories/GHSA-3m5v-4xp5-gjg2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:794d3d7801c17649afc47be54651cd8e8b1ef508d14c3e7e2a0e752f04431a62 · sha256:3599891a056c9a33… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.