Executive brief
SurrealDB is a multi-model database that supports complex data relationships. A security flaw allowed authenticated users to bypass table-level access controls by using graph traversal queries to reach restricted data. This could lead to unauthorized access to sensitive records that were intended to be hidden from the user, though the impact is limited to the specific database the user is already authorized to access.
Technical details
An authorization bypass exists in SurrealDB's graph traversal and 'REFERENCES TO' back-reference mechanisms. The root cause is that 'GraphEdgeScan' and 'ReferenceScan' operations fetch records directly from storage without routing them through the 'Document::pluck_select' function, which is responsible for enforcing table-level 'PERMISSIONS FOR select' clauses. An authenticated attacker with access to a starting table can traverse edges to reach and read full documents from target tables, even if those tables are explicitly configured with 'PERMISSIONS FOR select NONE'. This vulnerability is limited to confidentiality within the current database; namespace and database isolation remain intact. The issue is resolved in version 3.1.0 by implementing a permission cache that enforces checks during graph scans.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: disclosed
- 2026-07-01: advisory: GitHub Advisory published
- 2026-07-01: patched: Version 3.1.0 released