CVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Configurations

No configuration.

History

18 Jul 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-18 14:17

Updated : 2026-07-21 18:37


NVD link : CVE-2024-58366

Mitre link : CVE-2024-58366

CVE.ORG link : CVE-2024-58366


JSON object : View

Products Affected

No product.

CWE
CWE-134

Use of Externally-Controlled Format String