Junglewise Threat Intelligence

Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

Severity: low · CVSS 3.1 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: crates.io.

Executive brief

Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`

Affected products

  • crates.io surrealdb

Related threats