Junglewise Threat Intelligence

SurrealDB authorization bypass in JSON Patch copy and move operations

Severity: medium · CVSS 4.3 · Published 2026-07-01

Technologies: surrealdb (crates.io). Vendors: crates.io, SurrealDB.

Executive brief

SurrealDB, a multi-model database, contains a vulnerability that allows users to bypass security restrictions on specific data fields. By using a specially crafted update command, an authorized user could copy sensitive information they are not supposed to see into a field they can access. This could lead to the unauthorized exposure of private record data, though it is limited to the specific records the user already has permission to modify.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in SurrealDB's handling of JSON Patch operations within `UPDATE … PATCH` statements. When a `copy` or `move` operation is provided with an empty `from` pointer, the system interprets this as a request to copy the entire record into a destination field. Because the permission filter only masks original protected field names and not the new destination field, the sensitive values are returned to the caller in the response. This allows an authenticated attacker with update privileges to bypass field-level `SELECT` permissions. The issue is resolved in version 3.1.0 by rejecting empty `from` pointers during parsing.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: disclosed: Initial publication of the advisory
  • 2026-05-27: patched: Fix committed to repository
  • 2026-07-01: advisory: GitHub Advisory published

References

Related threats