← Vulnerability feed

Vulnerability record · CVE-2026-63739 · published 20 July 2026

CVE-2026-63739: Surrealdb path traversal vulnerability

Surrealdb · Surrealdb

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.

8.3 CVSS 4.0 High EPSS 0.48% · top 61.4% CWE-22 · Path traversal
8.3CVSS 4.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
22 Jul 2026Last modified by NVD

Description

SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-63739 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-71392Surrealdb command injection vulnerabilitySurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…EPSS 0.44%9.2CVE-2026-63756Surrealdb race condition vulnerabilitySurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …EPSS 0.37%9.0CVE-2024-58366Delskayn rquickjs vulnerabilitySurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers wit…EPSS 0.58%8.7CVE-2026-63760Surrealdb vulnerabilitySurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or…EPSS 0.52%8.7CVE-2026-63757Surrealdb missing authentication for critical function vulnerabilitySurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …EPSS 0.54%8.7CVE-2026-63747Surrealdb vulnerabilitySurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unau…EPSS 0.52%8.7CVE-2024-58362Surrealdb vulnerabilitySurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without re…EPSS 0.64%8.7CVE-2024-58368Surrealdb vulnerabilitySurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenti…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2026-63739), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.