Executive brief
Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`
Affected products
- crates.io surrealdb
Junglewise Threat Intelligence
Severity: low · CVSS 3.1 · Published 2026-07-20
Technologies: surrealdb (crates.io). Vendors: crates.io.
Duplicate Advisory: SurrealDB has bypass of field-level SELECT permissions through JSON Patch `copy` and `move` with empty `from`