{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/surrealdb-before-3.1.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-63739"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SurrealDB (before 3.1.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","arbitrary-file-read","database","cve"],"_cs_type":"advisory","_cs_vendors":["SurrealDB"],"content_html":"\u003cp\u003eA critical arbitrary file read vulnerability, tracked as CVE-2026-63739, has been identified in SurrealDB versions prior to 3.1.5. This flaw resides within the \u003ccode\u003eDEFINE ANALYZER mapper filter\u003c/code\u003e component of the database. Exploitation requires an attacker to possess existing authenticated access to the SurrealDB instance with either \u003ccode\u003eEDITOR\u003c/code\u003e or \u003ccode\u003eOWNER\u003c/code\u003e roles. By crafting a malicious query that injects arbitrary file paths into the mapper filter, an attacker can coerce the database to disclose the contents of files accessible by the SurrealDB process. This sensitive information is then retrieved through verbose database query error messages, particularly when the \u003ccode\u003eSURREAL_FILE_ALLOWLIST\u003c/code\u003e security control is not configured or is empty. This vulnerability poses a significant risk for data exfiltration and unauthorized information disclosure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to a vulnerable SurrealDB instance, holding either an \u003ccode\u003eEDITOR\u003c/code\u003e or \u003ccode\u003eOWNER\u003c/code\u003e role.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a database query using the \u003ccode\u003eDEFINE ANALYZER\u003c/code\u003e statement.\u003c/li\u003e\n\u003cli\u003eWithin the \u003ccode\u003emapper filter\u003c/code\u003e component of the \u003ccode\u003eDEFINE ANALYZER\u003c/code\u003e statement, the attacker injects a relative or absolute path to a target file on the server's filesystem (e.g., \u003ccode\u003e/etc/passwd\u003c/code\u003e or \u003ccode\u003eC:\\Windows\\System32\\drivers\\etc\\hosts\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe SurrealDB server processes this malformed query.\u003c/li\u003e\n\u003cli\u003eDuring the processing, if the \u003ccode\u003eSURREAL_FILE_ALLOWLIST\u003c/code\u003e is unconfigured or empty, the database attempts to access the specified arbitrary file path.\u003c/li\u003e\n\u003cli\u003eThe database generates an error message that inadvertently includes the full content of the targeted file.\u003c/li\u003e\n\u003cli\u003eThe attacker receives this detailed error message as part of the query response, thus exfiltrating the file's contents.\u003c/li\u003e\n\u003cli\u003eThis allows the attacker to read sensitive configuration files, credentials, or other critical data from the host system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-63739 allows an authenticated attacker to read any file accessible by the SurrealDB process on the host system. This can lead to the disclosure of highly sensitive information, such as system configuration files, database credentials, private keys, or other proprietary data, with a CVSS v3.1 base score of 7.7 (High). Such information could then be used for further privilege escalation, lateral movement, or complete system compromise. The specific damage depends on the sensitivity of the files readable by the SurrealDB process and the overall security posture of the environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade SurrealDB instances to version 3.1.5 or newer immediately to patch the CVE-2026-63739 vulnerability.\u003c/li\u003e\n\u003cli\u003eConfigure the \u003ccode\u003eSURREAL_FILE_ALLOWLIST\u003c/code\u003e security setting in SurrealDB to explicitly define and restrict which file paths the database process is permitted to access.\u003c/li\u003e\n\u003cli\u003eImplement strict principle of least privilege for all database users; ensure that users with \u003ccode\u003eEDITOR\u003c/code\u003e or \u003ccode\u003eOWNER\u003c/code\u003e roles only have necessary permissions and access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:25:47Z","date_published":"2026-07-20T12:25:47Z","id":"https://feed.craftedsignal.io/briefs/2026-07-surrealdb-file-read/","summary":"SurrealDB versions prior to 3.1.5 contain an arbitrary file read vulnerability (CVE-2026-63739) within the DEFINE ANALYZER mapper filter that allows authenticated database users with EDITOR or OWNER roles to read arbitrary files from the server filesystem by injecting file paths into query error messages, especially when the SURREAL_FILE_ALLOWLIST is unconfigured.","title":"SurrealDB Arbitrary File Read Vulnerability CVE-2026-63739","url":"https://feed.craftedsignal.io/briefs/2026-07-surrealdb-file-read/"}],"language":"en","title":"CraftedSignal Threat Feed - SurrealDB (Before 3.1.5)","version":"https://jsonfeed.org/version/1.1"}