CVE-2026-32247High· 8.1▾ MidnightPoC availableGraphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
1 GitHub repo
Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter construction for non-Kuzu backends. Attacker-controlled label values supplied through SearchFilters.node_labels were concatenated directly into Cypher label expressions without validation.
In MCP deployments, this was exploitable not only through direct untrusted access to the Graphiti MCP server, but also through prompt injection against an LLM client that could be induced to call search_nodes with attacker-controlled entity_types values. The MCP server mapped entity_types to SearchFilters.node_labels, which then reached the vulnerable Cypher construction path.
Affected backends included Neo4j, FalkorDB, and Neptune. Kuzu was not affected by the label-injection issue because it used parameterized label handling rather than string-interpolated Cypher labels.
This issue was mitigated in 0.28.2.
0.28.1 and earlier0.28.2search_nodes when used by an LLM client processing untrusted promptsBefore 0.28.2, Graphiti joined SearchFilters.node_labels with | and inserted the result directly into Cypher label expressions in the shared search-filter constructors used by non-Kuzu providers.
The vulnerable logic was effectively:
node_labels = '|'.join(filters.node_labels)node_label_filter = 'n:' + node_labelsThe same pattern was also used in edge-search filter construction.
In MCP deployments, search_nodes accepted an entity_types argument and passed it directly to SearchFilters(node_labels=entity_types). An attacker who could influence prompts processed by an LLM client with Graphiti MCP access could use prompt injection to steer the model into invoking search_nodes with crafted entity_types values containing Cypher syntax. Those values would then be interpolated into Cypher before 0.28.2.
Successful exploitation could allow arbitrary Cypher execution within the privileges of the configured graph database connection, including:
group_idsSeparately, the original report also identified a narrower issue in fulltext search query construction for unvalidated group_ids. That issue was distinct from the Cypher label-injection path described above and was also mitigated in 0.28.2.
Upgrade to 0.28.2 or later.
Version 0.28.2 added:
SearchFilters.node_labelsgroup_ids in shared search fulltext helpersIf you cannot upgrade immediately:
SearchFilters.node_labels or MCP entity_types@4n93L for their original report.
graphiti-core < 0.28.2Upgrade to a patched release:
graphiti-core 0.28.2Field changes observed since this record was first indexed.