Executive brief
SurrealDB is a database used for building real-time web applications. A security flaw allowed users to bypass access controls when deleting data; specifically, when a user deleted a data point (node), the system would automatically delete connected relationships (edges) even if the user was explicitly forbidden from doing so. This could lead to unauthorized data removal and the exposure of sensitive relationship details that should have remained hidden.
Technical details
An authorization bypass vulnerability exists in SurrealDB's graph edge handling. When a node is deleted, the `Document::purge_edges` function in `surrealdb/core/src/doc/delete.rs` is triggered to maintain graph consistency. In affected versions, this function executed with permissions explicitly disabled (`with_perms(false)`), causing the system to ignore `PERMISSIONS FOR delete` and `PERMISSIONS FOR select` clauses defined on edge tables. An authenticated attacker with permission to delete a node could leverage this to delete connected edges they are not authorized to modify and potentially observe edge state that should be restricted. The vulnerability is addressed in version 3.1.0 by ensuring the caller's permission context is propagated during the edge removal process.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-04-22: patched: Fix committed to repository
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-06-05: other: Version 3.1.0 released
- 2026-07-15: disclosed: CVE published to NVD