CVE-2026-6057
CRITICALUnauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution
Title source: cnaDescription
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
Scores
CVSS v3
9.8
EPSS
0.0015
EPSS Percentile
34.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-22
Status
published
Products (1)
FalkorDB/FalkorDB Browser
1.9.3
Published
Apr 10, 2026
Tracked Since
Apr 10, 2026