Medium severity4.3NVD Advisory· Published Jul 18, 2026· Updated Aug 13, 2026
CVE-2025-71394
CVE-2025-71394
Description
SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-2cvj-g5r5-jrrgnvdVendor Advisory
- www.vulncheck.com/advisories/surrealdb-before-local-file-read-via-define-analyzernvdThird Party Advisory
News mentions
0No linked articles in our index yet.