CVE-2026-10130 is an authentication bypass vulnerability in QueryWeaver. The vulnerability allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an [truncated]
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in its file upload API. The flaw allows remote attackers to write arbitrary files to the server filesystem, which can lead to remote code execution. The vulnerability is classified as CWE-22 (Path Traversal) and carries a CVSS 3.1 score of 9.8 (Critical), indicating network-based exploitation with low attack complexity, no req [truncated]