← Back to search

CVE-2026-88410

7.1 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw in FalkorDB's graph.UDF module allows unauthorized read operations, but no write commands are registered, leading to potential data exposure and integrity issues.
Exploitability
Exploitation requires access to the Redis instance and knowledge of the UDF usage patterns; it is moderately difficult.
Blast radius
If exploited, this could lead to sensitive data leakage within the application, impacting user privacy and system integrity.
Prioritized remediation
Update FalkorDB to version v4.20.5 or later which addresses this issue.
data-exposureredisudf

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.