SurrealDB Vulnerability Under Investigation
An early warning has been issued regarding a vulnerability in SurrealDB that appears to allow authenticated users to read full record data bypassing permission restrictions. This issue is under investigation and affects all tables within the attacker's current database.
What happened
Reports indicate that a vulnerability in SurrealDB enables authenticated users to bypass permission restrictions and read full record data from all tables within their current database. This issue is currently under investigation. To assess your exposure, check if you are using a version of SurrealDB prior to 3.1.0. It is recommended to upgrade to SurrealDB version 3.1.0 or later to mitigate this vulnerability. For more detailed information, consult the primary sources listed in the threat data section.
The vulnerability, tracked under multiple GHSA IDs including GHSA-98FX-66CF-FC7C, GHSA-HV6H-HC26-Q48P, and GHSA-VJJX-RFW4-RMFC, is part of a series of advisories issued by the SurrealDB team. These advisories cover a range of issues from bypassing access controls to privilege escalation and denial of service conditions. Engineers should review these advisories to understand the full scope of potential vulnerabilities and ensure their systems are updated accordingly.
How 0Day mitigates this
surrealdb is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.