FalkorDB QueryWeaver
- <= 0.2.0
An authentication bypass vulnerability has been identified in QueryWeaver versions through 0.2.0. This vulnerability allows unauthenticated attackers to obtain valid session tokens for existing accounts by sending a signup request with a known victim email address. The issue arises because the signup route creates and links a new token to the corresponding identity before verifying if the email is associated with an existing account. As a result, the server inadvertently returns a valid authenticated session token for the victim's identity, without requiring any prior credentials or user interaction.
Exploitation of this vulnerability allows for unauthorized access to user accounts by issuing valid session tokens for existing users.
To reproduce this vulnerability, send a signup request to the QueryWeaver application with an email address that belongs to an existing account. The server will respond with a valid session token for that account, bypassing authentication requirements.
Users are advised to update QueryWeaver to version 0.3.1 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.