Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 28, 2026
SurrealDB before 1.1.1 Format String via Scripting Functions
CVE-2024-58366
Description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4mitrevendor-advisory
- www.vulncheck.com/advisories/surrealdb-before-format-string-via-scripting-functionsmitrethird-party-advisory
News mentions
0No linked articles in our index yet.