Arbitrary File Read in SurrealDB Affects Database Users
CVE-2026-63739
8.3HIGH
What is CVE-2026-63739?
SurrealDB, before version 3.1.5, is vulnerable to an arbitrary file read issue due to a flaw in the DEFINE ANALYZER mapper filter. This vulnerability allows users with EDITOR or OWNER permissions to access files on the server where SurrealDB runs. If the SURREAL_FILE_ALLOWLIST is not set up or is empty, attackers could exploit this flaw to specify unauthorized file paths within the mapper filter, potentially leading to sensitive information disclosure via error messages. This issue emphasizes the importance of proper configuration and user privilege management in database environments.
Affected Version(s)
surrealdb 0 < 3.1.5
surrealdb 3.1.5
