Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2024-58362: SurrealDB accepts malicious data in signin and signup operations

CVE-2024-58362
Summary

SurrealDB versions 1.5.5 and earlier, and 2.0.0-beta versions before 2.0.0-beta.3, do not properly check data sent to signin and signup operations. This allows an attacker to execute unauthorized database actions if they can send malicious data to these operations. To fix this, update SurrealDB to the latest version.

Original title
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values....
Original description
SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of credentials. The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not affect IAM resources, which require the owner role).
nvd CVSS3.1 8.8
nvd CVSS4.0 8.7
Vulnerability type
CWE-75
Published: 18 Jul 2026 · Updated: 19 Jul 2026 · First seen: 18 Jul 2026