GHSA-qcfm-cmfw-f4x4CriticalCVSS 8.5

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception:...

Published
July 18, 2026
Last Modified
July 18, 2026

🔗 CVE IDs covered (1)

📋 Description

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

🔗 References (4)