PT-2026-60946 · Surrealdb+1 · Surrealdb+1

·

CVE-2024-58366

·

Published

2024-02-21

·

Updated

2026-08-13

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.1.1
Description A format string issue exists in the Exception::throw type() function of rquickjs, the Rust binding to the QuickJS engine, when scripting is enabled. Attackers with scripting privileges can provide format string sequences in error inputs to read arbitrary process memory or execute code with the privileges of the SurrealDB process.
Recommendations Update to version 1.1.1 or later. As a temporary mitigation, disable scripting functionality to prevent exploitation.

Exploit

Fix

RCE

Use of Externally-Controlled Format String

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-58366
GHSA-Q3GG-M8HR-H4X4

Affected Products

Surrealdb
Quickjs