Junglewise Threat Intelligence

SurrealDB permission bypass via WHERE clause evaluation

Severity: medium · CVSS 6.5 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: crates.io, SurrealDB.

Executive brief

SurrealDB is a multi-user database system that enforces table-level permissions to control which authenticated users can read sensitive records. Before version 3.1.0, the database evaluates user-supplied WHERE clauses in queries against the full record contents before checking permissions, allowing an attacker to extract unauthorized data through side-channel techniques (scripting functions, THROW statements, or timing analysis). Any authenticated database user, including those with minimal privileges, can read tables they should not have access to.

Technical details

The vulnerability exists in SurrealDB's query processing pipeline, where permission checks occur after WHERE clause evaluation rather than before. When a user submits a SELECT statement (or UPDATE/UPSERT/INSERT ON DUPLICATE KEY UPDATE/RELATE statement with SET/MERGE/CONTENT/PATCH clauses), the database evaluates side-effecting expressions in the WHERE clause against the full record data before invoking check_permissions_table. An authenticated attacker can exploit this ordering flaw to exfiltrate record contents through multiple vectors: direct exfiltration via scripting functions (when --allow-scripting is enabled), SurrealQL's THROW statement, or timing-based side channels in all configurations. The attack requires valid database authentication but no specific privileges. The vulnerability is scoped to the attacker's current database and does not cross namespace or database isolation boundaries. Patch version 3.1.0 introduced check_permissions_table execution before user-supplied expressions are evaluated and added regression tests for multiple update paths.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: disclosed: GHSA-98fx-66cf-fc7c published by SurrealDB project
  • 2026-07-20: disclosed: GHSA-4f9v-jpx9-mjvw published (duplicate advisory)
  • 2026: patched: Fixed in version 3.1.0
  • 2026-09-04: other: GHSA-4f9v-jpx9-mjvw withdrawn as duplicate of GHSA-98fx-66cf-fc7c

References

Related threats