Executive brief
SurrealDB, a multi-model cloud database, contains a security flaw where it fails to properly check user permissions during certain data queries. An authenticated user who has access to one part of the database can bypass security restrictions to read sensitive records from other tables by following data relationships (graph edges). This could lead to unauthorized access to private customer or business data, though the breach is limited to the specific database the user is already logged into.
Technical details
A vulnerability in SurrealDB's query execution engine allows for an authorization bypass (CWE-863/CWE-200). The root cause is that 'GraphEdgeScan' and 'ReferenceScan' operations fetch records directly from storage without routing them through the 'Document::pluck_select' function, which is responsible for evaluating 'PERMISSIONS FOR select' clauses. An authenticated attacker with network access to the database can craft SurrealQL queries that traverse graph edges or back-references to access tables even if they are explicitly marked as 'PERMISSIONS FOR select NONE'. This bypass can extend through multi-hop chains. The issue is resolved in version 3.1.0 by implementing a per-batch permission cache that enforces checks during graph scans.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: NVD publication date