LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-33286

graphiti · graphiti

Published
CVSS9.1
Severitycritical
WeaknessCWE-913
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Description

Graphiti is a framework that sits on top of models and exposes them via a JSON:API-compliant interface. Versions prior to 1.10.2 have an arbitrary method execution vulnerability that affects Graphiti's JSONAPI write functionality. An attacker can craft a malicious JSONAPI payload with arbitrary relationship names to invoke any public method on the underlying model instance, class or its associations. Any application exposing Graphiti write endpoints (create/update/delete) to untrusted users is affected. The `Graphiti::Util::ValidationResponse#all_valid?` method recursively calls `model.send(name)` using relationship names taken directly from user-supplied JSONAPI payloads, without validating

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33286

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33286.