⚠ Withdrawn by GitHub Security Advisories

Withdrawn: September 4, 2026

GHSA-h5q3-3v5q-v5j8CriticalCVSS 8.0Disclosed before NVD

Duplicate Advisory: SurrealDB server-takeover via SurrealQL injection on backup import

Published
July 18, 2026
Last Modified
September 4, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-ccj3-5p93-8p42. This link is maintained to preserve external references.

Original Description

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that let users define custom tables or fields are also exposed to a universal second-order SurrealQL injection even when query parameters are sanitized.

🎯 Affected products1

  • rust/surrealdb:< 2.0.5

🔗 References (4)