CVE-2024-58366
surrealdb surrealdb 취약점
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
- 대응 우선순위
- 점검
- CVSS
- 9
- EPSS
- 0.30% 백분위 22.3% · 2026.08.03 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.18