Junglewise Threat Intelligence

CVE-2024-58366: SurrealDB format string vulnerability in rquickjs scripting engine

CVE-2024-58366 · Severity: high · CVSS 8.5 · Published 2026-07-18

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a cloud-native database that supports advanced scripting functions. A vulnerability in its scripting engine allows users with script-execution privileges to trigger a memory error by providing specially crafted text. This could allow an attacker to read sensitive information from the server's memory or potentially take full control of the database process.

Technical details

A format string vulnerability (CWE-134) exists in the rquickjs crate, which provides Rust bindings for the QuickJS engine used by SurrealDB. The Exception::throw_type function incorrectly passed user-controlled error strings directly to a printf-style function without proper sanitization. An attacker with permissions to define or execute scripting functions can provide inputs containing format specifiers (e.g., %s, %x) to trigger undefined behavior. This can be leveraged to leak process memory or achieve remote code execution (RCE), though RCE complexity is increased by Rust's default exploit mitigations and a 256-byte limit on error messages. The vulnerability is only exploitable if scripting is explicitly enabled via --allow-scripting or --allow-all.

Affected products

  • SurrealDB SurrealDB < 1.1.1
  • SurrealDB rquickjs < 0.4.2

Timeline

  • 2024-02-19: advisory: GitHub Security Advisory published
  • 2026-07-18: disclosed: NVD publication date

References

Related threats