surrealdb-core
A scalable, distributed, collaborative, document-graph database, for the realtime web
Activity
- Latest release
- 4d ago
- Total releases
- 119
- Cadence
- ~5 days
- Last 12 months
- 49
Reach
- Downloads
- 1.4M
- Stars
- 33.0k
Details
- License
- unknown
- First release
- Jan 30, 2024
| Version | Released | |
|---|---|---|
3.3.0-beta.4
pre
|
3.3.0-beta.4
pre
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.1.6
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.6
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.3.0-beta.3
pre
|
3.3.0-beta.3
pre
Dependencies (105)
+ 97 more
Changelog
Compare changes
|
|
3.3.0-beta.2
pre
|
3.3.0-beta.2
pre
Dependencies (105)
+ 97 more
Changelog
Compare changes
|
|
3.3.0-beta.1
pre
|
3.3.0-beta.1
pre
Dependencies (105)
+ 97 more
Changelog
Compare changes
|
|
3.2.4
patch
|
3.2.4
patch
Dependencies (116)
+ 108 more
Changelog
Compare changes
|
|
3.2.3
patch
|
3.2.3
patch
Dependencies (116)
+ 108 more
Changelog
Compare changes
|
|
3.2.2
patch
|
3.2.2
patch
Dependencies (116)
+ 108 more
Changelog
Compare changes
|
|
3.2.1
patch
|
3.2.1
patch
Dependencies (116)
+ 108 more
Changelog
Compare changes
|
|
3.2.0
minor
|
3.2.0
minor
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
3.2.0-beta.3
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.3
pre
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
3.2.0-beta.2
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.2
pre
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
3.2.0-beta.1
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.2.0-beta.1
pre
Dependencies (117)
+ 109 more
Changelog
Compare changes
|
|
3.1.5
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.5
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.4
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.4
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.3
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.3
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.2
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.2
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.1
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.1
patch
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.0
minor
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.0
minor
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.0-beta.3
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.0-beta.3
pre
Dependencies (118)
+ 110 more
Changelog
Compare changes
|
|
3.1.0-beta.2
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.0-beta.2
pre
Dependencies (113)
+ 105 more
Changelog
Compare changes
|
|
3.1.0-beta.1
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.1.0-beta.1
pre
Dependencies (113)
+ 105 more
Changelog
Compare changes
|
|
3.0.5
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.5
patch
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
2.6.5
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.5
patch
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
2.6.4
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.4
patch
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.0.4
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.4
patch
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
3.0.3
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.3
patch
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
2.6.3
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.3
patch
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.0.2
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.2
patch
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
3.0.1
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.1
patch
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
3.0.0
major
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0
major
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
3.0.0-rc.1
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-rc.1
pre
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
2.6.2
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.2
patch
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
2.6.1
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.1
patch
Dependencies (108)
+ 100 more
Changelog
Compare changes
|
|
3.0.0-beta.4
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-beta.4
pre
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
3.0.0-beta.3
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-beta.3
pre
Dependencies (110)
+ 102 more
Changelog
Compare changes
|
|
2.6.0
minor
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.6.0
minor
Dependencies (108)
+ 100 more
Changelog
Compare changes
|
|
2.5.0
minor
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.5.0
minor
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.0.0-beta.2
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-beta.2
pre
Dependencies (113)
+ 105 more
Changelog
Compare changes
|
|
2.4.1
patch
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.4.1
patch
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.0.0-beta.1
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-beta.1
pre
Dependencies (114)
+ 106 more
Changelog
Compare changes
|
|
3.0.0-alpha.18
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.18
pre
Dependencies (114)
+ 106 more
Changelog
Compare changes
|
|
3.0.0-alpha.17
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.17
pre
Dependencies (116)
+ 108 more
Changelog
Compare changes
|
|
3.0.0-alpha.16
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.16
pre
Dependencies (115)
+ 107 more
Changelog
Compare changes
|
|
2.4.0
minor
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
2.4.0
minor
Dependencies (107)
+ 99 more
Changelog
Compare changes
|
|
3.0.0-alpha.14
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.14
pre
Dependencies (114)
+ 106 more
Changelog
Compare changes
|
|
3.0.0-alpha.13
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.13
pre
Dependencies (113)
+ 105 more
Changelog
Compare changes
|
|
3.0.0-alpha.12
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.12
pre
Dependencies (112)
+ 104 more
Changelog
Compare changes
|
|
3.0.0-alpha.11
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.11
pre
Dependencies (112)
+ 104 more
Changelog
Compare changes
|
|
3.0.0-alpha.10
pre
1 CVE
CVE-2026-63733
GHSA-66r2-5gwj-gxm2
Sep 04, 2026
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
A For example:
Any user allowed to update a ImpactOnly databases with a What an attacker can do:
What it can't do:
PatchesPermission clauses must now be read-only: defining or importing one that contains a write is rejected, and any write attempted while a clause is evaluated is blocked at runtime, including writes reached through a called function. Read-only clauses are unaffected.
WorkaroundsUsers unable to patch should consider the following workarounds:
Resources
AcknowledgementsThank you to sondt99 for reporting this issue. Fixed in
3.2.0
References
Updated Sep 04, 2026 · Source: OSV.dev |
3.0.0-alpha.10
pre
Dependencies (111)
+ 103 more
Changelog
Compare changes
|