CVE-2024-58366 – SurrealDB before 1.1.1 Format String via Scripting Functions

​CVE ID :CVE-2024-58366

Published : July 18, 2026, 2:17 p.m. | 5 hours, 4 minutes ago

Description :SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

Severity: 8.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More