PatchSiren

FalkorDB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FalkorDB CVE published 2026-07-18

CVE-2026-10130

CVE-2026-10130 is an authentication bypass vulnerability in QueryWeaver. The vulnerability allows unauthenticated attackers to obtain valid session tokens for existing accounts by submitting a signup request with a known victim email address. The signup route unconditionally creates and links a new token to the matching Identity via a Cypher MERGE operation before checking whether the email belongs to an [truncated]

CRITICAL FalkorDB CVE published 2026-04-10

CVE-2026-6057

FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in its file upload API. The flaw allows remote attackers to write arbitrary files to the server filesystem, which can lead to remote code execution. The vulnerability is classified as CWE-22 (Path Traversal) and carries a CVSS 3.1 score of 9.8 (Critical), indicating network-based exploitation with low attack complexity, no req [truncated]