CVE-2026-32247: Cypher injection in Graphiti search filters exploitable via prompt injection
Graphiti versions before 0.28.2 concatenated attacker-controlled label values from SearchFilters.node_labels directly into Cypher expressions, enabling Cypher injection on Neo4j, FalkorDB and Neptune backends. In MCP deployments it could be triggered by prompt injection against an LLM client induced to call search_nodes with attacker-controlled entity_types; fixed in 0.28.2.
Disclosed 12 March 2026 · Record updated 13 September 2026
Impact
Attacker-controlled input could be injected into Cypher label expressions against Neo4j, FalkorDB and Neptune backends of Graphiti's temporal context graph, including indirectly via prompt injection through the Graphiti MCP server. Kuzu backends were unaffected.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-32247
