PT-2026-60954 · Surrealdb · Surrealdb

·

CVE-2025-71393

·

Published

2025-04-10

·

Updated

2026-08-13

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 2.2.2
Description When scripting is enabled, the system fails to properly enforce recursion limits in cases where native functions contain embedded JavaScript that issues new queries. Authenticated attackers can bypass these limits by chaining native and JavaScript function calls, leading to infinite recursion and the exhaustion of server memory.
Recommendations Update to version 2.2.2 or later. Disable scripting functionality as a temporary mitigation measure.

Exploit

Fix

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-71393
GHSA-M7RC-8W7M-R9QR

Affected Products

Surrealdb