Description
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
Published: 2026-04-10
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Falkordb
Falkordb falkordb Browser
Vendors & Products Falkordb
Falkordb falkordb Browser

Fri, 10 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
Description FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
Title Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution
Weaknesses CWE-22
References

Subscriptions

Falkordb Falkordb Browser
cve-icon MITRE

Status: PUBLISHED

Assigner: securin

Published:

Updated: 2026-04-10T20:25:53.551Z

Reserved: 2026-04-10T00:33:01.535Z

Link: CVE-2026-6057

cve-icon Vulnrichment

Updated: 2026-04-10T20:25:10.352Z

cve-icon NVD

Status : Received

Published: 2026-04-10T10:16:04.547

Modified: 2026-04-10T21:16:28.800

Link: CVE-2026-6057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T14:40:49Z

Weaknesses