SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Metrics
Affected Vendors & Products
References
History
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Surrealdb
Surrealdb surrealdb |
|
| Vendors & Products |
Surrealdb
Surrealdb surrealdb |
Mon, 20 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. | |
| Title | SurrealDB before 1.1.1 Format String via Scripting Functions | |
| Weaknesses | CWE-134 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-18T13:10:06.939Z
Updated: 2026-07-20T15:13:48.265Z
Reserved: 2026-07-18T12:40:52.916Z
Link: CVE-2024-58366
Updated: 2026-07-20T15:13:43.968Z
No data.
No data.