SurrealDB Command-Line Tool Vulnerability: SurrealQL Injection Risk
- Severity
- HIGH
- Affected component
- surrealdb (cargo)
- Affected versions
- >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3
- Patched version
- >=2.2.2
An early warning has been issued regarding a vulnerability in the SurrealDB command-line tool that may allow SurrealQL injection when reimporting backups.
What happened
It has been reported that the SurrealDB command-line tool does not properly sanitize table or field names during database exports. This oversight may lead to a SurrealQL injection vulnerability when the exported backup is reimported. The vulnerability is under investigation and has not yet been exploited in the wild.
The affected versions include surrealdb (cargo) versions >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3.
To assess your exposure, check the version of SurrealDB you are using against the affected version ranges provided. If your version falls within any of the affected ranges, you are potentially vulnerable to this issue.
What to do about it
- Immediately upgrade to SurrealDB version 2.2.2 or later to mitigate the risk of SurrealQL injection.
- Review your backup and restore processes to ensure they are secure and do not inadvertently introduce vulnerabilities.
- Monitor the primary sources for updates on this vulnerability and any additional mitigation advice that may be released.
How 0Day would have caught this
surrealdb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if you are using surrealdb (cargo) versions >= 2.0.0, < 2.1.4 or >= 2.2.0, < 2.2.2 or < 2.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or < 2.0.5 or >= 2.1.0, < 2.1.5 or < 2.5.0 or >= 3.0.0-alpha.1, < 3.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.5 or >= 2.0.0-beta.1, < 2.0.0-beta.3 or < 3.1.0 or < 3.1.0 or < 1.1.0 or < 3.1.0 or < 3.1.0 or < 1.2.0 or < 3.1.4 or < 1.2.1 or < 2.0.4 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.5.4 or >= 2.0.0-alpha.1, < 2.0.0-alpha.6 or < 2.1.0 or >= 3.0.0, < 3.1.5 or < 3.1.5 or >= 3.1.0, < 3.1.5 or < 2.1.0 or < 1.1.1 or >= 3.0.0, < 3.1.5 or < 1.1.0 or < 2.1.0 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 1.1.1 or < 3.1.0 or < 3.1.0 or >= 2.0.0, < 2.0.4 or >= 2.2.0, < 2.2.2 or >= 2.1.0, < 2.1.5 or < 2.0.5 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 3.1.0 or < 1.0.1 or < 2.6.1 or >= 3.0.0-alpha.8, < 3.0.0-beta.3.
What should I do right now?
Upgrade to SurrealDB version 2.2.2 or later to mitigate the risk of SurrealQL injection. Review your backup and restore processes for security and monitor the primary sources for updates.
Is there an official fix available?
Yes, the official fix is to upgrade to SurrealDB version 2.2.2 or later.