CVE-2024-58366
surrealdb
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
- CVSS
- 9
- EPSS
- 0.30% 22.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.18