Intel

AIKIDO-2026-10268

graphiti-core is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 2, 2026

24

Low Risk

This Affects:

PYTHONgraphiti-core
0.0.1 - 0.27.1
Fixed in 0.28.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to sensitive information exposure through application log output. Certain debug or operational log statements may include personally identifiable information (PII) or other confidential internal data, which could be accessed by unauthorized parties with log access. This creates a risk of unintended disclosure of sensitive information.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

graphiti-core is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 0.27.1.

How to fix this

Upgrade the graphiti-core library to the patch version.