CVE-2026-63739: SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREALFILEALLOWLIST is empty or not configured.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.5 - Configuration
Set SURREAL_FILE_ALLOWLIST to a non-empty allowlist so that it is not empty or unconfigured; this mitigates arbitrary file path specification and arbitrary file read via query error messages.
SurrealDB DEFINE ANALYZER mapper filter SURREAL_FILE_ALLOWLIST = non-empty (required)
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63739?
The severity of CVE-2026-63739 is high with a score of 8.3.
How does CVE-2026-63739 affect SurrealDB?
CVE-2026-63739 allows database users with EDITOR or OWNER roles to perform arbitrary file read operations through the DEFINE ANALYZER mapper filter.
What versions of SurrealDB are affected by CVE-2026-63739?
SurrealDB versions prior to 3.1.5 are affected by CVE-2026-63739.
How can I mitigate CVE-2026-63739?
To mitigate CVE-2026-63739, it is recommended to upgrade SurrealDB to version 3.1.5 or later.
Who can exploit CVE-2026-63739?
Attackers with EDITOR or OWNER roles in SurrealDB can exploit CVE-2026-63739 to read arbitrary files accessible to the process.