Feed/CVE-2025-71394
CVE-2025-71394MEDIUMCVSS 4.3

CVE-2025-71394

Published Jul 18, 2026·Updated Aug 13, 2026

NVD Description

SurrealDB versions before 2.2.2 contain a local file read vulnerability in the DEFINE ANALYZER statement that allows authenticated users to read arbitrary files on the file system. Attackers with root, namespace, or database level privileges can point analyzers to arbitrary file paths and exfiltrate content from two-column tab-separated files.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free