CVE-2025-71394: SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 2.2.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-71394?
The severity of CVE-2025-71394 is classified as low with a CVSS score of 4.0.
How do I fix CVE-2025-71394?
To fix CVE-2025-71394, upgrade SurrealDB to version 2.2.2 or later.
What type of vulnerability is CVE-2025-71394?
CVE-2025-71394 is a local file read vulnerability due to path traversal.
Who is affected by CVE-2025-71394?
Authenticated users and attackers with root, namespace, or database level privileges are affected by CVE-2025-71394.
What can attackers do with CVE-2025-71394?
Attackers can exploit CVE-2025-71394 to read arbitrary files on the file system by pointing analyzers to arbitrary file paths.