Impact
SurrealDB prior to version 3.1.5 has a flaw in the DEFINE ANALYZER mapper filter that allows database users holding EDITOR or OWNER roles to read files accessible to the SurrealDB process. By specifying arbitrary file paths in the mapper filter, such users can obtain file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured. This results in an unauthorized disclosure of local files and can lead to the compromise of sensitive data held on the host machine.
Affected Systems
The affected product is SurrealDB from the vendor surrealdb, for all releases before 3.1.5. Any deployment running these versions is vulnerable unless a later update is applied.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity vulnerability. The EPSS score of 0.35% indicates a very low but nonzero exploitation probability, and the lack of a CISA KEV listing does not diminish the need for remediation. The attack vector is inferred to be remote, as an attacker can authenticate as a user with EDITOR or OWNER privileges to trigger the file‑read behavior. Exploitation requires only that the SurrealDB process has file system‑level access, consequently the risk of exploitation is significant for any misconfigured or poorly role‑managed instance.
OpenCVE Enrichment