VYPR
Unrated severityNVD Advisory· Published Jul 18, 2026· Updated Jul 28, 2026

SurrealDB before 1.1.1 Format String via Scripting Functions

CVE-2024-58366

Description

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.