Junglewise Threat Intelligence

CVE-2025-71392: SurrealDB SurrealQL injection in command-line export

CVE-2025-71392 · Severity: critical · CVSS 4 · Published 2026-07-18

Vendors: SurrealDB.

Executive brief

SurrealDB is a database platform that supports exporting and importing backups via command-line tools. A vulnerability in the export function fails to properly sanitize table and field names, allowing an authenticated user with elevated privileges to embed malicious database commands that execute when a backup is imported by a higher-privileged user. This can result in complete compromise of the database, including unauthorized root-level access and data manipulation.

Technical details

This vulnerability is a second-order SurrealQL injection flaw in SurrealDB's export/import functionality (CWE-77: Command Injection). The root cause is improper escaping of special characters in table and field names during the export process. An authenticated System User with OWNER or EDITOR roles can create tables or fields containing malicious SurrealQL syntax. When the exported backup is later reimported by a user with higher privileges (such as a system administrator), the injected SQL commands execute with those elevated privileges. This enables privilege escalation and complete server takeover. The vulnerability affects versions prior to 2.0.5, 2.1.5, and 2.2.2. It requires authentication and user interaction (import operation by a higher-privileged user), but no network-specific preconditions beyond database access. Patches have been released and workarounds involve manual inspection of exports before importing.

Affected products

  • SurrealDB SurrealDB < 2.0.5, >= 2.1.0 and < 2.1.5, >= 2.2.0 and < 2.2.2

Timeline

  • 2025-04-11: disclosed
  • 2025-04-11: patched: Versions 2.0.5, 2.1.5, 2.2.2 and later released with fixes

References