Executive brief
SurrealDB is a multi-model database used for managing complex data relationships. A vulnerability in the database's relationship handling allows users who only have permission to create new records to accidentally or intentionally overwrite existing data. This could lead to unauthorized data modification or loss of integrity in the database records.
Technical details
An improper authorization vulnerability exists in SurrealDB's RELATE statement processing. When a RELATE statement includes a 'SET id' clause pointing to an existing edge ID, the storage layer silently overwrites the target record instead of returning an error. This allows an authenticated attacker with CREATE permissions to bypass UPDATE permission requirements and modify existing edge records. The issue was resolved in version 3.1.0 by ensuring the RELATE path uses 'put_record' logic, which correctly returns a 'RecordExists' error upon conflict.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: NVD publication date