SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSurrealdb
APPSurrealdb< 3.1.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2026-63756CRITICAL9.2PL ✓same product
SurrealDB: Race condition w /rpc umożliwia przejęcie sesji uwierzytelnionej
CVE-2025-71392CRITICAL9.4PL ✓same product
SurrealDB: injection SurrealQL przez eksport — privilege escalation
CVE-2024-58366CRITICAL9.0PL ✓same product
Format string vulnerability w SurrealDB — RCE przez scripting
CVE-2026-63737HIGH7.1PL ✓same product
SurrealDB — DoS poprzez przepełnienie stosu wywołaniami łańcuchów operatorów
CVE-2026-63735HIGH8.6PL ✓same product
SurrealDB — brak walidacji zakresu w niestandardowych trasach API