Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2024-58366: SurrealDB before 1.1.1 allows attackers to read memory or execute code
CVE-2024-58366
CVE-2024-58366
Summary
An outdated version of SurrealDB contains a security flaw that lets attackers access sensitive information or take control of the database. This affects SurrealDB versions before 1.1.1, and it's essential to update to the latest version to prevent unauthorized access. If you're running an affected version, update to SurrealDB 1.1.1 or later as soon as possible.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| surrealdb | surrealdb |
< 1.1.1 < 0.4.2 |
Original title
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string ...
Original description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
nvd CVSS3.1
8.5
nvd CVSS4.0
9.0
Vulnerability type
CWE-134
Published: 18 Jul 2026 · Updated: 20 Jul 2026 · First seen: 18 Jul 2026