⚠ Withdrawn by GitHub Security Advisories
Withdrawn: September 4, 2026
GHSA-6g69-7xmf-h2x7MediumCVSS 4.3Disclosed before NVD
Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions
📋 Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-66r2-5gwj-gxm2. This link is maintained to preserve external references.
Original Description
SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.
🎯 Affected products1
- rust/surrealdb:< 3.2.0