THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-66r2-5gwj-gxm2 (medium) — SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

[GHSA] GHSA-66r2-5gwj-gxm2 (medium) — SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

highgithub_advisoriesPublished 2026-09-04

GHSA-66r2-5gwj-gxm2 Severity: medium CVE: CVE-2026-63733

SurrealDB: Writes in a PERMISSIONS clause bypass table permissions

A `PERMISSIONS ... WHERE` clause is evaluated with permission enforcement disabled, so it can't recurse into its own checks. But the clause could also contain data-modifying statements, and these ran with enforcement still off — so evaluating a permission check could write

Indicators of compromise

Original source: https://github.com/advisories/GHSA-66r2-5gwj-gxm2