Impact
SurrealDB prior to version 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can inject format string sequences in error inputs, allowing them to read arbitrary memory or execute code within the SurrealDB process. This flaw can lead to a local or remote compromise of the database server with full process privileges. Based on the description, it is inferred that the attack vector involves the scripting engine.
Affected Systems
The vulnerable product is SurrealDB versions prior to 1.1.1. All installations with scripting enabled are affected, regardless of operating system.
Risk and Exploitability
Based on the description, it is inferred that the primary attack vector is the scripting engine. The vulnerability has a CVSS score of 9, indicating critical severity, while the EPSS score of < 1% indicates a very low exploitation probability. It is not listed in the CISA KEV catalog. Attackers who can run scripts in SurrealDB can exploit the flaw by sending malicious error input. If the database is exposed to untrusted clients, the risk extends to remote attackers; disabling or restricting scripting reduces exposure.
OpenCVE Enrichment