Executive brief
SurrealDB is a database that supports real-time data updates through 'LIVE' queries. A vulnerability was found where these real-time updates continue to be sent to a user even after their session has expired, they have logged out, or they have switched to a different account on the same connection. This could allow a user to continue seeing sensitive data updates they are no longer authorized to access until the network connection is manually closed.
Technical details
A vulnerability in SurrealDB's LIVE SELECT mechanism causes subscriptions to retain the initial authentication state ($auth, $token, etc.) indefinitely. The server evaluates table- and row-level PERMISSIONS using this stale state rather than the current session state. Consequently, if a session is invalidated, expires via TTL, or the user re-authenticates as a different principal on the same connection, the original subscription remains active and continues delivering notifications. This is a confidentiality-only issue (CWE-613) as it does not permit unauthorized writes. The issue is resolved in version 3.1.0 by ensuring RPC methods like signin, signup, and invalidate properly trigger a cleanup of associated live queries.
Affected products
- SurrealDB surrealdb < 3.1.0
Timeline
- 2026-05-27: disclosed: Initial disclosure in surrealdb/surrealdb repository
- 2026-07-01: advisory: GitHub Advisory published