CVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:delskayn:rquickjs:*:*:*:*:*:rust:*:*
cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-18 14:17

Updated : 2026-08-13 16:03


NVD link : CVE-2024-58366

Mitre link : CVE-2024-58366

CVE.ORG link : CVE-2024-58366


JSON object : View

Products Affected

surrealdb

  • surrealdb

delskayn

  • rquickjs
CWE
CWE-134

Use of Externally-Controlled Format String