CVE-2026-6057 Details
Description
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
A path traversal vulnerability has been identified in FalkorDB Browser version 1.9.3. This vulnerability exists in the file upload API, where remote attackers can exploit the lack of proper authentication and validation to write arbitrary files. This file writing capability can be leveraged to execute remote code on the server.
Users can update to the latest version of FalkorDB Browser, which includes a patch for this vulnerability. Instructions for updating are available in the FalkorDB Browser repository on GitHub.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 10, 2026CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FalkorDB/falkordb-browser | securin | ProductVendor |
| https://github.com/FalkorDB/falkordb-browser/pull/1611 | securin | Issue TrackingVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | securin |
Affected Products
| Product | Versions |
|---|---|
| FalkorDB Browser | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | securin |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | New CVE Received | securin |
Volerion