CVE-2025-11060
Surrealdb: surrealdb is vulnerable to unauthorized data exposure via live query subscriptions
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.7EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
26 set 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/security/cve/CVE-2025-11060https://bugzilla.redhat.com/show_bug.cgi?id=2394708https://github.com/surrealdb/surrealdbhttps://github.com/surrealdb/surrealdb/commit/d81169a06b89f0c588134ddf2d62eeb8d5e8fd0chttps://github.com/surrealdb/surrealdb/pull/6247https://github.com/surrealdb/surrealdb/security/advisories/GHSA-7vm2-j586-vcvchttps://surrealdb.com/docs/surrealql/statements/live