High severity8.5NVD Advisory· Published Jul 18, 2026· Updated Aug 13, 2026
CVE-2024-58366
CVE-2024-58366
Description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4nvdVendor Advisory
- www.vulncheck.com/advisories/surrealdb-before-format-string-via-scripting-functionsnvdThird Party Advisory
News mentions
0No linked articles in our index yet.