Impact
SurrealDB versions before 3.1.0 allow an authenticated user to bypass permission checks within LIVE SELECT subscriptions. Permission expressions that reference the special parameters $value, $before, $after, or $event evaluate against attacker‑controlled bindings rather than the actual document contents. This flaw is a permission‑management error (CWE‑863) and can lead to unauthorized disclosure of data that should be restricted by the database’s access controls.
Affected Systems
Any SurrealDB installation running a version earlier than 3.1.0 is affected, regardless of deployment size or configuration. The vulnerability impacts the SURrealDB product distributed by the vendor surrealdb:surrealdb.
Risk and Exploitability
The CVSS score of 5.3 designates a moderate severity. An EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user who can bind values to the special parameter names and register a LIVE SELECT query; no additional access or privileged context is needed. While no active exploitation has been publicly reported, the flaw’s presence in broadly deployed databases warrants timely remediation.
OpenCVE Enrichment