SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE …
Medium CVSS 4.3
Summary
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing to an existing edge id, causing the storage layer to silently overwrite the target record instead of rejecting the operation.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-f82j-v89j-mf86 Vendor Advisory
- https://www.vulncheck.com/advisories/surrealdb-before-relate-statement-record-overwrite Third Party Advisory
Timeline
- nvd_ingest NVD