← back
CVE-2026-6057criticalCWE-22

Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution

28Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9.8epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H