Executive brief
FalkorDB Browser, a visualization tool for the FalkorDB database, contains a critical security flaw in its file upload feature. An unauthenticated attacker can exploit this to upload malicious files to the server, potentially leading to a complete takeover of the system and access to sensitive data. This vulnerability poses a severe risk to the confidentiality and integrity of the database environment.
Technical details
A path traversal vulnerability (CWE-22) exists in the file upload API of FalkorDB Browser version 1.9.3. The vulnerability stems from insufficient validation of user-supplied file paths and a lack of authentication on the upload endpoint. A remote, unauthenticated attacker can exploit this by sending a specially crafted request to upload arbitrary files to sensitive locations on the server filesystem. This can be leveraged to achieve remote code execution (RCE). A fix involving session validation and improved file path validation has been merged into the project's staging branch.
Affected products
- FalkorDB FalkorDB Browser 1.9.3
Timeline
- 2026-04-09: patched: Fix merged into staging branch via Pull Request 1611
- 2026-04-10: disclosed: Initial disclosure date
- 2026-04-10: advisory: NVD publication date