Unauthenticated Path Traversal in FalkorDB Browser Leads to Remote Code Execution
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.9%
exploitation probability
0.9%top 43% of all CVEs
observed exploitation
nono source reports it
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
FalkorDB · FalkorDB Browser