Back to overview

CVE-2026-6057

CRITICAL
9.8
CVSS 3.1
Description
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

Metadata

CVE ID
CVE-2026-6057
State
PUBLISHED
Assigner
securin
Reserved
2026-04-10 00:33 UTC
Published
2026-04-10 09:16 UTC
Last updated
2026-04-10 20:25 UTC
Primary CWE
CWE-22
CWE-22 Path Traversal
Vendor / Product
FalkorDB / FalkorDB Browser
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
FalkorDB FalkorDB Browser Linux,64 bit,Windows 1.9.3
Weakness (CWE)
CWESourceDescription
CWE-22 cna CWE-22 Path Traversal
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview