Executive brief
SurrealDB, a multi-model database, contains a security flaw that allows users with basic access to bypass data restrictions. By using specific database update commands, an authorized user can copy sensitive information they are not supposed to see into fields they can access. This could lead to the unauthorized exposure of protected record data, though it does not allow for full database takeover or service disruption.
Technical details
A vulnerability in SurrealDB's implementation of JSON Patch operations (via UPDATE...PATCH or db.patch()) allows for field-level SELECT permission bypass. When performing a 'copy' or 'move' operation, providing an empty 'from' pointer causes the database to treat the source as the entire record. An authenticated attacker can duplicate all fields of a record—including those restricted by field-level permissions—into a new destination field that the attacker has permission to read. The fix, introduced in version 3.1.0, involves rejecting empty 'from' pointers during the parsing of JSON Patch operations.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: advisory: Initial GitHub Security Advisory published
- 2026-07-20: disclosed: NVD publication date