CARGO · JULY 2026 · EARLY WARNING

SurrealDB Vulnerability: SurrealQL Injection Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
surrealdb (cargo)
Affected versions
>= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3
Patched version
Not yet available
GHSA-H5Q3-3V5Q-V5J8GHSA-CCJ3-5P93-8P42

SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 are reportedly vulnerable to SurrealQL injection and privilege escalation due to improper escaping of table and field names in the command-line export command.

What happened

SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fail to properly escape table and field names in the command-line export command. This vulnerability allows for SurrealQL injection and privilege escalation, affecting the rust/surrealdb package. The vulnerability has been tracked with IDs GHSA-H5Q3-3V5Q-V5J8 and GHSA-CCJ3-5P93-8P42. It was first flagged on July 18, 2026.

The affected components include surrealdb (cargo) with various version ranges as specified in the threat data. The vulnerability has not been reported as exploited in the wild, and there is no indication of a supply-chain attack at this time. The primary source indicates that this is a duplicate advisory, and the vulnerability details should be consulted directly from the source.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If surrealdb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, or 2.2.x before 2.2.2.

What should I do right now?

Upgrade to SurrealDB 2.0.5, 2.1.5, or 2.2.2 to mitigate the risk.

Where can I find more information?

Consult the primary sources and the threat data provided for detailed information.

Sources

Join the 0Day waitlist →

← Back to all threats