CVE-2026-88410
Received Received - Intake

Graph UDF Unregistered Write Command in FalkorDB

Vulnerability report for CVE-2026-88410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-21

Last updated on: 2026-09-21

Assigner: MITRE

Description

The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected behavior within the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-21
Last Modified
2026-09-21
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The vulnerability in FalkorDB (Redis module) versions 4.20.1 to 4.20.4 involves the graph.UDF function not being registered as a write command. This can cause unexpected behavior in the application, potentially leading to unintended data modifications or disruptions.

Impact Analysis

This vulnerability may allow unauthorized users to execute write operations through the graph.UDF function, potentially leading to data corruption, loss of integrity, or application instability. It could also enable attackers to manipulate data if they gain access to the system.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR, HIPAA, or other standards as it involves unexpected behavior due to a misregistered write command in FalkorDB. However, if exploited, it could lead to unauthorized data modifications, potentially violating integrity requirements in compliance frameworks.

Mitigation Strategies

Upgrade FalkorDB to a version where the graph.UDF is properly registered as a write command. Avoid using vulnerable versions (v4.20.1 to v4.20.4) until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88410. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart