THREAT OPS › Threat News › [GHSA] GHSA-848m-r628-vrxw (high) — SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
[GHSA] GHSA-848m-r628-vrxw (high) — SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
GHSA-848m-r628-vrxw Severity: high CVE: CVE-2026-63735
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
An authenticated user scoped to one namespace/database could invoke a custom API (`DEFINE API`) belonging to a different namespace/database, reaching another tenant's endpoint.
The route `/api/{namespace}/{database}/{endpoint}` took the nam
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-63735cve
- https://surrealdb.com/docs/surrealql/statements/define/apiurl
- https://surrealdb.com/docs/surrealdb/security/capabilitiesurl
Original source: https://github.com/advisories/GHSA-848m-r628-vrxw