VYPR
Medium severity4.3NVD Advisory· Published Jul 18, 2026· Updated Aug 13, 2026

CVE-2025-71394

CVE-2025-71394

Description

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Surrealdb/Surrealdbllm-fuzzy2 versions
    <2.2.2+ 1 more
    • (no CPE)range: <2.2.2
    • cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*range: <2.1.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.