Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6fpj-mjq4-fp9r

Опубликовано: 20 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 5.4

Описание

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by setting same-named body fields to spoofed values that permission checks incorrectly read instead of the immutable id key.

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by setting same-named body fields to spoofed values that permission checks incorrectly read instead of the immutable id key.

EPSS

Процентиль: 8%
0.0018
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 5.4
nvd
22 дня назад

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by setting same-named body fields to spoofed values that permission checks incorrectly read instead of the immutable id key.

EPSS

Процентиль: 8%
0.0018
Низкий

5.3 Medium

CVSS4

5.4 Medium

CVSS3

Дефекты

CWE-639