SurrealDB Vulnerability: SurrealQL Injection Risk
- Severity
- HIGH
- Affected component
- surrealdb (cargo)
- Affected versions
- >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3
- Patched version
- Not yet available
SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 are reportedly vulnerable to SurrealQL injection and privilege escalation due to improper escaping of table and field names in the command-line export command.
What happened
SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fail to properly escape table and field names in the command-line export command. This vulnerability allows for SurrealQL injection and privilege escalation, affecting the rust/surrealdb package. The vulnerability has been tracked with IDs GHSA-H5Q3-3V5Q-V5J8 and GHSA-CCJ3-5P93-8P42. It was first flagged on July 18, 2026.
The affected components include surrealdb (cargo) with various version ranges as specified in the threat data. The vulnerability has not been reported as exploited in the wild, and there is no indication of a supply-chain attack at this time. The primary source indicates that this is a duplicate advisory, and the vulnerability details should be consulted directly from the source.
What to do about it
- Upgrade to SurrealDB 2.0.5, 2.1.5, or 2.2.2 to mitigate the risk of SurrealQL injection and privilege escalation.
- Review your project dependencies to identify any use of the affected surrealdb (cargo) versions.
- If you are using an affected version, plan and execute an upgrade to one of the patched versions as soon as possible.
- Monitor the primary sources for any updates or additional information regarding this vulnerability.
How 0Day would have caught this
surrealdb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, or 2.2.x before 2.2.2.
What should I do right now?
Upgrade to SurrealDB 2.0.5, 2.1.5, or 2.2.2 to mitigate the risk.
Where can I find more information?
Consult the primary sources and the threat data provided for detailed information.