Executive brief
SurrealDB is a multi-model database that allows fine-grained control over who can see specific data fields. A vulnerability was found where users could bypass these field-level protections by using specific database relationship queries (graph traversals) instead of direct lookups. This could allow an authorized user to view sensitive information within records they already have general access to, potentially leading to unauthorized data exposure.
Technical details
An authorization bypass exists in SurrealDB's query execution engine. The 'resolve_record_batch' helper, utilized by GraphEdgeScan and ReferenceScan, fails to apply field-level SELECT permissions and read-time COMPUTED field filtering. While table-level permissions and row-level WHERE predicates are still enforced, an authenticated user can retrieve raw record data for restricted fields by materializing records through graph-edge (->), back-reference (<~), or target-vertex traversals. This issue affects versions 3.1.0 through 3.1.4 and is fixed in version 3.1.5.
Affected products
- SurrealDB SurrealDB >= 3.1.0, < 3.1.5
Timeline
- 2026-06-19: disclosed
- 2026-06-19: advisory
- 3.1.5: patched