CVE-2026-6057

CRITICAL

Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution

Title source: cna

Description

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

Scores

CVSS v3 9.8
EPSS 0.0015
EPSS Percentile 34.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-22
Status published
Products (1)
FalkorDB/FalkorDB Browser 1.9.3
Published Apr 10, 2026
Tracked Since Apr 10, 2026