CVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

Scoring

Severity
CRITICAL
CVSS base score
9
CVSS vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
EPSS probability
0.32%
CWE
CWE-134
Published
2026-07-18
Last modified
2026-07-28

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs