CVE-2024-58366

HIGH

SurrealDB before 1.1.1 Format String via Scripting Functions

Title source: cna
STIX 2.1

Description

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-q3gg-m8hr-h4x4)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-q3gg-m8hr-h4x4
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 1.1.1 Format String via Scripting Functions
https://www.vulncheck.com/advisories/surrealdb-before-format-string-via-scripting-functions

Scores

CVSS v3 8.5
EPSS 0.0030
EPSS Percentile 22.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-134
Status published
Products (4)
surrealdb/surrealdb < 0.4.2
surrealdb/surrealdb < 1.1.1
surrealdb/surrealdb 0.4.2
surrealdb/surrealdb 1.1.1
Published Jul 18, 2026
Tracked Since Jul 18, 2026