CyberRota Analysis
AI-GeneratedSurrealDB versions prior to 3.1.0 are vulnerable to an authorization bypass that allows authenticated users to spoof composite record-id field values through editable body fields. This flaw enables attackers to circumvent permission rules, potentially compromising tenant isolation and accessing unauthorized data. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data access.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by setting same-named body fields to spoofed values that permission checks incorrectly read instead of the immutable id key.
Related CVEs
Other vulnerabilities affecting the same vendor(s)