CVE-2024-58366 - 8.5 High
⚠️ CVE-Referenzen:
CVE-2024-58366
CVE-2025-71392
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Quelle: app.opencve.io