Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-58366— SurrealDB before 1.1.1 Format String via Scripting Functions

CVSS 8.5 · High EPSS 0.30% · P22

Possible ATT&CK Techniques 1AI

T1203 · Exploitation for Client Execution

Affected Version Matrix 4

VendorProductVersion RangeStatus
surrealdbsurrealdb< 1.1.1affected
1.1.1unaffected
< 0.4.2affected
0.4.2unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-58366

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SurrealDB before 1.1.1 Format String via Scripting Functions
Source: NVD (National Vulnerability Database)
Vulnerability Description
SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
使用外部控制的格式字符串
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
surrealdbsurrealdb 0 ~ 1.1.1 -
surrealdbsurrealdb 0 ~ 0.4.2 -

II. Public POCs for CVE-2024-58366

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 9491 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2024-58366

登录查看更多情报信息。

Vendor Advisories for CVE-2024-58366 (2)

Same Patch Batch · surrealdb · 2026-07-18 · 24 CVEs total

CVE-2024-583628.8 HIGHSurrealDB before 1.5.5 Query Injection via RPC API
CVE-2023-543668.8 HIGHSurrealDB before 1.0.1 Insecure Default Table Permissions
CVE-2024-583687.5 HIGHSurrealDB before 1.1.0 Denial of Service via HTTP Headers
CVE-2024-583646.5 MEDIUMSurrealDB before 1.2.1 Denial of Service via Parsing Error
CVE-2024-583596.5 MEDIUMSurrealDB before 2.1.0 Denial of Service via rand() Sorting
CVE-2024-583576.5 MEDIUMSurrealDB before 2.1.0 Denial of Service via rand::time()
CVE-2024-583706.5 MEDIUMSurrealDB before 1.1.0 Uncontrolled Recursion Denial of Service
CVE-2024-583616.5 MEDIUMSurrealDB before 2.0.4 Denial of Service via Parser Exception
CVE-2024-583656.5 MEDIUMSurrealDB before 1.2.0 Denial of Service via Nonexistent Function
CVE-2024-583696.5 MEDIUMSurrealDB before 1.1.1 Denial of Service via Global Parameters
CVE-2024-583636.3 MEDIUMSurrealDB before 1.5.4 Authentication Bypass via Database Switch
CVE-2024-583584.9 MEDIUMSurrealDB before 2.1.0 Denial of Service via Nonexistent Role
CVE-2025-71396SurrealDB before 2.2.2 Denial of Service via JavaScript Scripting
CVE-2025-71395SurrealDB before 2.2.2 Memory Exhaustion via string::replace
CVE-2025-71393SurrealDB before 2.2.2 Memory Exhaustion via Nested Functions
CVE-2025-71397SurrealDB before 2.2.2 CPU Exhaustion via nested FOR loops
CVE-2025-71391SurrealDB before 2.2.2 Denial of Service via /sql endpoint
CVE-2025-71394SurrealDB before 2.2.2 Local File Read via DEFINE ANALYZER
CVE-2025-71390SurrealDB before 2.3.6 deny-net Bypass via DNS Resolution
CVE-2025-71398SurrealDB before 2.2.2 SSRF via HTTP Redirect Bypass

Showing top 20 of 24 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2024-58366

No comments yet


Leave a comment