Junglewise Threat Intelligence

CVE-2026-6057: FalkorDB Browser path traversal in file upload API

CVE-2026-6057 · Severity: critical · CVSS 9.8 · Published 2026-04-10

Vendors: FalkorDB.

Executive brief

FalkorDB Browser, a visualization tool for the FalkorDB database, contains a critical security flaw in its file upload feature. An unauthenticated attacker can exploit this to upload malicious files to the server, potentially leading to a complete takeover of the system and access to sensitive data. This vulnerability poses a severe risk to the confidentiality and integrity of the database environment.

Technical details

A path traversal vulnerability (CWE-22) exists in the file upload API of FalkorDB Browser version 1.9.3. The vulnerability stems from insufficient validation of user-supplied file paths and a lack of authentication on the upload endpoint. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to sensitive locations on the server filesystem. This can be leveraged to achieve remote code execution (RCE). A fix involving session validation and improved file path validation has been merged into the project's staging branch.

Affected products

  • FalkorDB FalkorDB Browser 1.9.3

Timeline

  • 2026-04-09: patched: Fix merged into staging branch via Pull Request 1611
  • 2026-04-10: disclosed: Initial disclosure date
  • 2026-04-10: advisory: NVD publication date

References