CVE-2024-58366

Source
https://cve.org/CVERecord?id=CVE-2024-58366
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58366.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-58366
Aliases
Published
2026-07-18T13:10:06.939Z
Modified
2026-08-15T11:45:15.666103760Z
Severity
  • 9.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
SurrealDB before 1.1.1 Format String via Scripting Functions
Details

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/58xxx/CVE-2024-58366.json",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "fixed": "0.4.2"
                }
            ]
        }
    ],
    "cwe_ids": [
        "CWE-134"
    ],
    "cna_assigner": "VulnCheck"
}
References

Affected packages

Git / github.com/delskayn/rquickjs

Affected ranges

Type
GIT
Repo
https://github.com/delskayn/rquickjs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:delskayn:rquickjs:*:*:*:*:*:rust:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "0.4.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/surrealdb/surrealdb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*",
    "source": [
        "AFFECTED_FIELD",
        "CPE_RANGE"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.1.1"
        }
    ]
}

Affected versions

0.*
0.1.0
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.2.0
0.2.1
0.2.2
0.3.0
0.3.1
v0.*
v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.19
v0.1.2
v0.1.20
v0.1.21
v0.1.22
v0.1.23
v0.1.24
v0.1.25
v0.1.26
v0.1.27
v0.1.28
v0.1.29
v0.1.3
v0.1.30
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9
v0.3.0
v0.4.0
v0.4.0-beta.0
v0.4.0-beta.1
v0.4.0-beta.2
v0.4.0-beta.3
v0.4.0-beta.4
v1.*
v1.0.0
v1.0.0-beta.1
v1.0.0-beta.10
v1.0.0-beta.11
v1.0.0-beta.12
v1.0.0-beta.2
v1.0.0-beta.3
v1.0.0-beta.4
v1.0.0-beta.5
v1.0.0-beta.6
v1.0.0-beta.7
v1.0.0-beta.8
v1.0.0-beta.9
v1.0.0-beta.9+20230402
v1.1.0
v1.1.0-beta.1
v1.1.0-beta.2
v1.1.0-beta.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-58366.json"