Arbitrary File Read in SurrealDB Affects Database Users
CVE-2026-63739

8.3HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63739?

SurrealDB, before version 3.1.5, is vulnerable to an arbitrary file read issue due to a flaw in the DEFINE ANALYZER mapper filter. This vulnerability allows users with EDITOR or OWNER permissions to access files on the server where SurrealDB runs. If the SURREAL_FILE_ALLOWLIST is not set up or is empty, attackers could exploit this flaw to specify unauthorized file paths within the mapper filter, potentially leading to sensitive information disclosure via error messages. This issue emphasizes the importance of proper configuration and user privilege management in database environments.

Affected Version(s)

surrealdb 0 < 3.1.5

surrealdb 3.1.5

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kah-ja
.