GHSA-vmg6-53r4-jhpw

Suggest an improvement
Source
https://github.com/advisories/GHSA-vmg6-53r4-jhpw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-vmg6-53r4-jhpw/GHSA-vmg6-53r4-jhpw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vmg6-53r4-jhpw
Withdrawn
2026-09-04T18:21:04Z
Published
2026-07-18T15:31:47Z
Modified
2026-09-04T19:00:04Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-27vq-hv74-7cqp. This link is maintained to preserve external references.

Original Description

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied. As a result, a client authorized to run queries may continue to access data in that table that the updated (but unapplied) permissions were intended to restrict.

Database specific
{
    "cwe_ids":  [
        "CWE-276"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-04T18:21:04Z",
    "nvd_published_at":  "2026-07-18T14:17:08Z",
    "severity":  "LOW"
}
References

Affected packages

crates.io / surrealdb

Package

Name
surrealdb
View open source insights on deps.dev
Purl
pkg:cargo/surrealdb

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0

Database specific

last_known_affected_version_range
"< 2.1.4"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-vmg6-53r4-jhpw/GHSA-vmg6-53r4-jhpw.json"