Description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Published: 2026-07-18
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB prior to version 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can inject format string sequences in error inputs, allowing them to read arbitrary memory or execute code within the SurrealDB process. This flaw can lead to a local or remote compromise of the database server with full process privileges. Based on the description, it is inferred that the attack vector involves the scripting engine.

Affected Systems

The vulnerable product is SurrealDB versions prior to 1.1.1. All installations with scripting enabled are affected, regardless of operating system.

Risk and Exploitability

Based on the description, it is inferred that the primary attack vector is the scripting engine. The vulnerability has a CVSS score of 9, indicating critical severity, while the EPSS score of < 1% indicates a very low exploitation probability. It is not listed in the CISA KEV catalog. Attackers who can run scripts in SurrealDB can exploit the flaw by sending malicious error input. If the database is exposed to untrusted clients, the risk extends to remote attackers; disabling or restricting scripting reduces exposure.

Generated by OpenCVE AI on July 30, 2026 at 23:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 1.1.1 or later
  • If an upgrade is not possible, disable scripting in the SurrealDB configuration to prevent exploitation
  • Ensure only trusted users have scripting privileges and enforce strict role‑based access controls

Generated by OpenCVE AI on July 30, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Mon, 20 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Title SurrealDB before 1.1.1 Format String via Scripting Functions
Weaknesses CWE-134
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:47:52.571Z

Reserved: 2026-07-18T12:40:52.916Z

Link: CVE-2024-58366

cve-icon Vulnrichment

Updated: 2026-07-20T15:13:43.968Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses
  • CWE-134

    Use of Externally-Controlled Format String