Executive brief
SurrealDB is a multi-model database platform used as a backend for applications requiring fine-grained access control. A flaw in versions before 2.0.4 allows authenticated users with limited permissions to read sensitive field values they should not have access to, through various query manipulation techniques. This could enable data leakage and unauthorized information disclosure in applications relying on field-level permissions for data protection.
Technical details
The vulnerability stems from improper authorization enforcement in SurrealDB's query processing pipeline, specifically CWE-285 (Improper Authorization). The root cause is that field permissions were validated after query operations rather than before, allowing multiple bypass techniques: SELECT VALUE queries skip permission checks on non-iterable return values; field aliasing bypasses permissions by checking against the aliased field name instead of the original; functions receive field values before permission filtering; WHERE clauses leak information via side-channels; UPDATE/DELETE operations expose record contents via RETURN BEFORE; and UPDATE SET clauses can reference unpermitted fields. The attack requires network access and low privileges (authenticated database user), with no user interaction needed. An attacker can extract protected field contents despite lacking SELECT permissions on those fields. Patched in version 2.0.4, which reorders permission evaluation to occur before document modifications.
Affected products
- SurrealDB SurrealDB < 2.0.4
- SurrealDB surrealdb-core < 2.0.4
Timeline
- 2024-10-08: disclosed: Original advisory GHSA-9722-9j67-vjcr published
- 2024-10-08: patched: Fixed in version 2.0.4
- 2026-07-18: advisory: Duplicate advisory GHSA-j9rh-f527-3x87 published
- 2026-09-04: other: Duplicate advisory withdrawn as duplicate of GHSA-9722-9j67-vjcr