PT-2026-61555 · Surrealdb · Surrealdb
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SurrealDB versions prior to 3.1.5
Description
An arbitrary file read issue exists in the DEFINE ANALYZER mapper filter. Database users with EDITOR or OWNER roles can read files accessible to the SurrealDB process by specifying arbitrary file paths in the mapper filter. The file contents are then retrieved through query error messages, provided that the
SURREAL FILE ALLOWLIST variable is empty or not configured.Recommendations
Update SurrealDB to version 3.1.5 or later.
Configure the
SURREAL FILE ALLOWLIST variable to restrict file access.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surrealdb