VYPR
High severity8.8NVD Advisory· Published Jul 18, 2026· Updated Aug 12, 2026

CVE-2024-58362

CVE-2024-58362

Description

SurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without recursively validating it for non-computed values. When a record access method defines a SIGNIN or SIGNUP query and the RPC API is exposed to untrusted users, an unauthenticated attacker can encode a binary object containing a subquery using the bincode serialization format and supply it in place of credentials. The subquery is then executed within the database owner's SIGNIN/SIGNUP query under a system user session with the editor role, allowing the attacker to select, create, update, and delete non-IAM resources (though not view the query results directly, and not affect IAM resources, which require the owner role).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
surrealdbcrates.io
>= 0

Affected products

4
  • cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*range: <1.5.5
    • cpe:2.3:a:surrealdb:surrealdb:2.0.0:beta1:*:*:*:*:*:*
    • cpe:2.3:a:surrealdb:surrealdb:2.0.0:beta2:*:*:*:*:*:*
    • (no CPE)range: <1.5.5, <2.0.0-beta.3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.