CVE-2025-71392

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that let users define custom tables or fields are also exposed to a universal second-order SurrealQL injection even when query parameters are sanitized.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-18 14:17

Updated : 2026-08-13 14:29


NVD link : CVE-2025-71392

Mitre link : CVE-2025-71392

CVE.ORG link : CVE-2025-71392


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')