SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.
References
| Link | Resource |
|---|---|
| https://github.com/surrealdb/surrealdb/security/advisories/GHSA-cc8f-fcx3-gpjr | Vendor Advisory Mitigation |
| https://www.vulncheck.com/advisories/surrealdb-before-arbitrary-file-read-via-define-analyzer | Third Party Advisory |
Configurations
History
22 Jul 2026, 15:49
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Surrealdb
Surrealdb surrealdb |
|
| References | () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-cc8f-fcx3-gpjr - Vendor Advisory, Mitigation | |
| References | () https://www.vulncheck.com/advisories/surrealdb-before-arbitrary-file-read-via-define-analyzer - Third Party Advisory | |
| CPE | cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* |
20 Jul 2026, 12:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-20 12:19
Updated : 2026-07-22 15:49
NVD link : CVE-2026-63739
Mitre link : CVE-2026-63739
CVE.ORG link : CVE-2026-63739
JSON object : View
Products Affected
surrealdb
- surrealdb
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
