Impact
QueryWeaver has an authentication bypass that allows an unauthenticated attacker to get a valid session token for any existing account by sending a signup request with a known email address. The server merges a new token with the matching identity before verifying the email, so the attacker receives a token that logs the victim in without needing credentials. Because the token is issued before any authentication check, this flaw lets attackers compromise accounts, exfiltrate data, or perform actions as the victim, representing a high-impact security exposure.
Affected Systems
Affected vendors and products include FalkorDB’s QueryWeaver service. Version information was not supplied in the advisory, so all installations of QueryWeaver that have not yet been verified against the published patch should be considered vulnerable.
Risk and Exploitability
The CVSS base score of 8.8 indicates a high severity; the EPSS score of less than 1% shows a low current exploitation probability, but the flaw remains in the public domain and could be leveraged by attackers with knowledge of target email addresses. The vulnerability is not listed in CISA KEV, yet the attack could be carried out remotely by any user with Internet access, making it a critical risk that deserves prompt attention.
OpenCVE Enrichment