CVE-2025-71392: SurrealDB before 2.2.2 SurrealQL Injection via export
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that let users define custom tables or fields are also exposed to a universal second-order SurrealQL injection even when query parameters are sanitized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.0.5 - Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.1.5 - Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71392?
CVE-2025-71392 has a critical severity rating of 9.4.
How do I fix CVE-2025-71392?
To fix CVE-2025-71392, upgrade SurrealDB to version 2.2.2 or later.
What type of vulnerability is CVE-2025-71392?
CVE-2025-71392 is a SurrealQL injection vulnerability related to command-line export.
Who is affected by CVE-2025-71392?
Authenticated System Users with OWNER or EDITOR roles in SurrealDB versions before 2.2.2 are affected by CVE-2025-71392.
What can attackers do with CVE-2025-71392?
Attackers can exploit CVE-2025-71392 to create tables or fields with malicious names that execute SurrealQL.