Junglewise Threat Intelligence

SurrealDB information disclosure via error messages

Severity: medium · CVSS 4.3 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: crates.io, SurrealDB.

Executive brief

SurrealDB is an open-source database management system that supports field-level access control to restrict which users can view specific data fields. A vulnerability in versions before 3.1.0 allows authenticated users with UPDATE permissions to read hidden fields by intentionally triggering error messages that expose field values. An attacker could read sensitive customer data, API keys, or other confidential information that was intended to be protected by access controls.

Technical details

This is an information disclosure vulnerability (CWE-209) in SurrealDB's error handling for arithmetic and extend operations. The root cause is that when UPDATE permission checks evaluate against unreduced documents, arithmetic operators and extend operations embed raw operand values into error messages without sanitization. An authenticated attacker with UPDATE access can trigger type incompatibility errors (e.g., attempting string + integer) on hidden fields, causing the field value to be included in the resulting error message. This bypasses field-level SELECT permissions that should restrict access. The vulnerability requires authentication and UPDATE privilege on the affected records, but no user interaction. A patch in version 3.1.0 replaced raw operand values with type names ("string", "int", "array", etc.) in error messages, eliminating the information disclosure.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: disclosed: Original advisory GHSA-6g9v-7gq3-p2c6 published
  • 2026-07-20: advisory: Duplicate advisory GHSA-p7hp-79jj-q923 published
  • 2026-05-27: patched: Patched in version 3.1.0

References

Related threats