CVE-2026-32247 is a Cypher injection vulnerability in Graphiti, a framework for building and querying temporal context graphs for AI agents. Versions prior to 0.28.2 improperly constructed Cypher search filters for non-Kuzu backends by concatenating attacker-controlled label values from SearchFilters.node_labels directly into Cypher label expressions without validation. The vulnerable path was part of shared search-filter construction used by affected graph backends including Neo4j, FalkorDB, and Neptune. In MCP deployments, exploitation was possible either through direct untrusted access to the Graphiti MCP server or indirectly via prompt injection against an LLM client that could be induced to invoke search_nodes with attacker-controlled entity_types values. The MCP server mapped entity_types to SearchFilters.node_labels, allowing untrusted input to reach the vulnerable Cypher construction logic. Kuzu was not affected because it handled labels using parameterized mechanisms rather than string-interpolated Cypher labels.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal standalone PoC for CVE-2026-32247 affecting getzep graphiti-core. Structure is simple: a README describing the vulnerability, impact, affected files, and exploitation path, plus a single Python script (poc.py) that reproduces the vulnerable logic from graphiti_core/search/search_filters.py by joining attacker-controlled node_labels with '|' and prefixing them with 'n:' for insertion into a Cypher WHERE clause. The exploit is not an automated end-to-end remote exploit; it is a proof-of-concept that demonstrates how crafted label strings can terminate the intended expression, introduce new Cypher clauses via WITH/MATCH, and comment out the remainder with '//'. Demonstrated capabilities include full graph data exfiltration, cross-tenant bypass of group_id filtering, and destructive graph deletion using DETACH DELETE. The documented attack path is through MCP tool input, specifically search_nodes arguments.entity_types flowing into SearchFilters without validation. No hardcoded remote host, IP, or callback infrastructure is present; the repository focuses on illustrating the injection primitive and example payloads rather than delivering a weaponized exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.