Impact
A race condition in the HTTP /rpc endpoint allows unauthenticated attackers to inherit authenticated session state, enabling them to perform privileged operations. The vulnerability is a time‑of‑check/time‑of‑use flaw (CWE‑362).
Affected Systems
SurrealDB versions earlier than 3.1.0 from the vendor surrealdb are affected. No specific sub‑versions are listed, so all releases before 3.1.0 are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.2 signifies critical severity, although the EPSS score is < 1%, indicating a very low but nonzero likelihood of real‑world exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly reported exploits as of the last update. Attackers can exploit the flaw by sending concurrent requests to the /rpc endpoint while an authenticated session exists, potentially hijacking privileged actions.
OpenCVE Enrichment