A critical vulnerability tracked as CVE-2025-71392 affects SurrealDB versions before 2.0.5, 2.1.5, and 2.2.2, allowing SurrealQL injection through the command-line export function. The flaw is caused by improper escaping of table and field names, enabling an authenticated user with OWNER or EDITOR privileges to create malicious object names that are written into exported backups.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
SurrealDB addressed a critical SurrealQL injection flaw in releases 2.0.5, 2.1.5, and 2.2.2. The issue affected earlier versions and involved improper escaping of table and field names in the command-line export function, enabling privilege escalation when a backup was later imported by a higher-privileged user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.