Executive brief
SurrealDB is a multi-model database that uses field-level permissions to restrict access to sensitive data columns. Versions 3.1.0 through 3.1.4 fail to enforce these field-level restrictions when records are accessed via graph relationships or back-references, allowing authenticated users to read hidden fields they should not have access to. This allows data exposure for fields that are intended to be restricted.
Technical details
This is an authorization bypass vulnerability (CWE-863) in SurrealDB's query execution layer. The root cause is that the resolve_record_batch helper function, which materializes full records for graph-edge traversals (→) and back-reference traversals (←~), only enforces table-level SELECT permissions and fails to apply field-level filtering. While direct SELECT queries and fetch_record operations properly filter fields using build_field_state and filter_fields_by_permission, traversal queries bypass this filtering logic. An authenticated user with table-level SELECT access on a table can exploit this by querying through graph relationships (e.g., person:bob→(SELECT * FROM knows)) to retrieve fields marked with DEFINE FIELD permissions that should be hidden. The vulnerability is network-accessible, requires low privileges (table-level SELECT), and has low complexity. Patched in version 3.1.5, which applies field-level permissions and computed fields in the resolve_record_batch function.
Affected products
- SurrealDB SurrealDB >=3.1.0, <3.1.5
Timeline
- 2026-06-19: disclosed
- 2026-07-20: advisory
- 2026-06-19: patched: Version 3.1.5 released with fix