A AegiFlow
MEDIUMCVSS 5.3

GHSA-6g69-7xmf-h2x7

Duplicate Advisory: Writes in a PERMISSIONS clause bypass table permissions

Published
2026-07-20
Modified
2026-09-04
Sources
github-advisory

Summary

## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-66r2-5gwj-gxm2. This link is maintained to preserve external references. ## Original Description SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.

Affected packages

EcosystemPackageAffected versionsFixed versions
rustsurrealdb

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.