← Vulnerability feed

Vulnerability record · CVE-2025-71392 · published 18 July 2026

CVE-2025-71392: Surrealdb command injection vulnerability

Surrealdb · Surrealdb

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that let users define custom tables or fields are also exposed to a universal second-order SurrealQL injection even when query parameters are sanitized.

9.4 CVSS 4.0 Critical EPSS 0.44% · top 64.1% CWE-77 · Command injection
9.4CVSS 4.0 base score
0.44%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
13 Aug 2026Last modified by NVD

Description

SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL. When a higher-privileged user subsequently imports the exported backup, the injected SurrealQL executes, enabling privilege escalation and root-level takeover of the SurrealDB instance. Applications that let users define custom tables or fields are also exposed to a universal second-order SurrealQL injection even when query parameters are sanitized.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-71392 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2026-63756Surrealdb race condition vulnerabilitySurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …EPSS 0.37%9.0CVE-2024-58366Delskayn rquickjs vulnerabilitySurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers wit…EPSS 0.58%8.7CVE-2026-63760Surrealdb vulnerabilitySurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or…EPSS 0.52%8.7CVE-2026-63757Surrealdb missing authentication for critical function vulnerabilitySurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …EPSS 0.54%8.7CVE-2026-63747Surrealdb vulnerabilitySurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unau…EPSS 0.52%8.7CVE-2024-58362Surrealdb vulnerabilitySurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without re…EPSS 0.64%8.7CVE-2024-58368Surrealdb vulnerabilitySurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenti…EPSS 0.65%8.7CVE-2023-54366Surrealdb incorrect default permissions vulnerabilitySurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables witho…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2025-71392), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.