SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Delskayn
Delskayn rquickjs |
|
| CPEs | cpe:2.3:a:delskayn:rquickjs:*:*:*:*:*:rust:*:* | |
| Vendors & Products |
Delskayn
Delskayn rquickjs |
Tue, 28 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Surrealdb
Surrealdb surrealdb |
|
| Vendors & Products |
Surrealdb
Surrealdb surrealdb |
Mon, 20 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 18 Jul 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges. | |
| Title | SurrealDB before 1.1.1 Format String via Scripting Functions | |
| Weaknesses | CWE-134 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-07-18T13:10:06.939Z
Updated: 2026-07-28T01:47:52.571Z
Reserved: 2026-07-18T12:40:52.916Z
Link: CVE-2024-58366
Updated: 2026-07-20T15:13:43.968Z
Status : Analyzed
Published: 2026-07-18T14:17:09.600
Modified: 2026-08-13T16:03:58.630
Link: CVE-2024-58366
No data.