SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
References
Configurations
No configuration.
History
18 Jul 2026, 14:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-18 14:17
Updated : 2026-07-21 18:37
NVD link : CVE-2024-58366
Mitre link : CVE-2024-58366
CVE.ORG link : CVE-2024-58366
JSON object : View
Products Affected
No product.
CWE
CWE-134
Use of Externally-Controlled Format String
