mediumCVSS 4.3Vulnerability

GHSA-4m82-p8cx-f94j

A `LIVE SELECT` subscription records the user's auth state (`$auth`, `$token`, `$session`, `$access`) when it is registered, and the server uses that recorded state to evaluate the table- and row-level `PERMISSIONS` clauses for every subsequent notification. The recorded state is never refreshed. When something changes the user's effective auth state — the originating session is invalidated, the session's TTL expires, or the user signs in, signs up, or authenticates as a different identity on the same connection — the subscription keeps delivering notifications under the old, stale auth state, and the `PERMISSIONS` that should now apply to the connection are never consulted. ### Impact A user whose session has been revoked, expired, signed out of, or re-authenticated on the same connection continues to receive real-time notifications evaluated against the prior principal. The attacker does not gain access to new resources — only continued access to resources the prior principal was already permitted to read — but that continued access persists past the point the principal change should have ended it, and persists indefinitely until the originating connection is closed. This is confidentiality-only: the dispatcher does not enable writes evaluated under the stranded principal. ### Patches - **`invalidate()` and TTL expiry** — `RpcProtocol::invalidate` now calls `cleanup_lqs(session_id)` after clearing the session, dropping every LIVE owned by the now-invalidated session. The notification dispatcher additionally reads the originating session's `exp` and skips delivery once it has passed, closing the TTL-expiry leg without requiring the `Session` object to remain in memory. - **Principal change on `signin` / `signup` / `authenticate` / `refresh`** — each of these RPC methods now snapshots the session's auth principal (`Auth::id()` + `Auth::level()`) before mutating the session and, if the principal has changed after the operation, calls `cleanup_lqs(session_id)`.

Properties

ghsa_id
GHSA-4m82-p8cx-f94j
severity
medium
summary
SurrealDB: LIVE query subscriptions survive session state changes, bypassing access controls
cvss_score
4.3
cve_id
GHSA-4m82-p8cx-f94j
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-07-01T20:16:12Z
source_url
https://github.com/advisories/GHSA-4m82-p8cx-f94j
ghsa_updated
2026-07-01T20:16:12Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Insufficient Session Expiration

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]rust/surrealdb

AFFECTS (1)

[Software]rust/surrealdb

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-4m82-p8cx-f94j (CVSS 4.3) — Ninja Signal Threat Intelligence | Ninja Signal