CVE-2025-71394

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-18 14:17

Updated : 2026-08-13 15:03


NVD link : CVE-2025-71394

Mitre link : CVE-2025-71394

CVE.ORG link : CVE-2025-71394


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')