Home

Description

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.

PUBLISHED Reserved 2026-04-10 | Published 2026-04-10 | Updated 2026-04-10 | Assigner securin

Problem types

CWE-22 Path Traversal

Product status

Default status
unaffected

1.9.3
affected

Credits

Ramesh Gunnam from Securin finder

References

github.com/FalkorDB/falkordb-browser

github.com/FalkorDB/falkordb-browser/pull/1611

cve.org (CVE-2026-6057)

nvd.nist.gov (CVE-2026-6057)

Download JSON