⚠ Withdrawn by GitHub Security Advisories

Withdrawn: September 4, 2026

GHSA-6g69-7xmf-h2x7MediumCVSS 4.3Disclosed before NVD

Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions

Published
July 20, 2026
Last Modified
September 4, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-66r2-5gwj-gxm2. This link is maintained to preserve external references.

Original Description

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.

🎯 Affected products1

  • rust/surrealdb:< 3.2.0

🔗 References (4)