Junglewise Threat Intelligence

CVE-2025-71394: SurrealDB local file read in DEFINE ANALYZER statement

CVE-2025-71394 · Severity: medium · CVSS 4 · Published 2026-07-18

Vendors: SurrealDB.

Executive brief

SurrealDB is a multi-model database used for managing and scaling data applications. A vulnerability in the database's analyzer definition feature allows authorized users to read sensitive files directly from the server's local storage. While an attacker needs existing database credentials to exploit this, it could lead to the exposure of system configuration files or other sensitive data stored on the host machine.

Technical details

A path traversal vulnerability (CWE-22) exists in SurrealDB's 'DEFINE ANALYZER' statement. Authenticated users with root, namespace, or database level privileges can provide arbitrary file paths to the analyzer. If the targeted file is formatted as a two-column tab-separated (TSV) file, the analyzer can be used to exfiltrate its contents. The vulnerability was addressed by introducing a 'SURREAL_FILE_ALLOWLIST' environment variable to restrict file access to approved paths. Patches are available in versions 2.1.5 and 2.2.2.

Affected products

  • SurrealDB SurrealDB < 2.1.5, < 2.2.2

Timeline

  • 2025-04-10: advisory: Initial GitHub Security Advisory published
  • 2026-07-18: disclosed: NVD publication date

References