CVE-2026-63739

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

22 Jul 2026, 15:49

Type Values Removed Values Added
First Time Surrealdb
Surrealdb surrealdb
References () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-cc8f-fcx3-gpjr - () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-cc8f-fcx3-gpjr - Vendor Advisory, Mitigation
References () https://www.vulncheck.com/advisories/surrealdb-before-arbitrary-file-read-via-define-analyzer - () https://www.vulncheck.com/advisories/surrealdb-before-arbitrary-file-read-via-define-analyzer - Third Party Advisory
CPE cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

20 Jul 2026, 12:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:49


NVD link : CVE-2026-63739

Mitre link : CVE-2026-63739

CVE.ORG link : CVE-2026-63739


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')