neo4j-graphrag is vulnerable to Improper Input Validation
65
Medium Risk
Text2CypherRetriever previously executed LLM-generated Cypher directly, which could be coerced via prompt injection into destructive/write queries (e.g., DETACH DELETE). It now runs EXPLAIN first (read-only) to determine the query type and refuses to execute anything not classified as read-only, raising Text2CypherRetrievalError.
You are affected if you are using a version that falls within the vulnerable range.
neo4j-graphrag is vulnerable to Improper Input Validation in versions 0.0.1 - 1.15.0.
Upgrade the neo4j-graphrag library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant