CVE-2025-71392
SurrealDB fails to properly escape table and field names during the command-line export process. This allows an attacker to inject malicious commands into these names, which execute when a higher-privileged user imports the exported data.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of SurrealDB versions before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2, particularly those running applications that allow users to define custom tables or fields.
Real-world impact
An attacker with basic editor permissions can escalate their privileges to gain full root-level control over the entire database instance.
Why this severity
The critical score reflects that an attacker can achieve full system takeover by exploiting a flaw in how the database handles exported data.
What to do about it
- 01Update to SurrealDB version 2.0.5, 2.1.5, or 2.2.2 or later.
NVD description
Timeline
- Jul 18, 2026 · 15d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.