Executive brief
SurrealDB is a NoSQL database that uses permission rules to control which data users can read. The vulnerability allows users with limited "record" access to read array elements that should be hidden by field-level permission rules. An attacker can systematically recover denied data by exploiting an off-by-one indexing bug in the permission filter. This only affects confidentiality and requires the attacker to already have basic read access to the affected table.
Technical details
The vulnerability is an incorrect authorization flaw (CWE-863) in SurrealDB's permission filter logic. When a `SELECT` permission is defined on array elements using `DEFINE FIELD field.* PERMISSIONS FOR select`, the filter in three code paths (doc/reduce.rs, doc/output.rs, exec/operators/scan/pipeline.rs) removes denied elements by index while iterating forward through the array. Because array removal shifts all subsequent indices down by one, the loop's remaining index references become invalid, leaving some denied elements in the result. The attack requires the attacker to already have SELECT access to the table and a valid record session; root and owner sessions are not affected. The fix (commit 8f89b260b) processes removals in reverse index order to prevent index invalidation. Field-level permissions remain correctly enforced.
Affected products
- SurrealDB SurrealDB <= 3.1.3
Timeline
- 2026-06-10: disclosed: Published to GitHub Advisory Database
- 2026-08-14: patched: Fix included in SurrealDB 3.1.4