Impact
SurrealDB database versions prior to 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement. Authenticated users who possess sufficient privileges—root, namespace, or database level—can create an analyzer that points to an arbitrary file path. When the analyzer processes a two‑column tab‑separated file, the content of the referenced file is exfiltrated, allowing the attacker to read local files on the system.
Affected Systems
All SurrealDB installations running a version before 2.2.2 are affected. This includes any release such as 2.2.1 and earlier. The vulnerability is vendor‑specific to SurrealDB and is tied to the database schema for analyzer definitions and file handling.
Risk and Exploitability
The CVSS score of 2.3 reflects a low severity impact limited to authenticated users. The EPSS score is below 1%, indicating a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers without authentication cannot exploit the flaw; the likely local and requires privileged access to the database. An attacker who already has a legitimate authenticated session could read sensitive configuration or application files that reside on the same filesystem as the SurrealDB instance.
OpenCVE Enrichment