CVE-2024-58366
SurrealDB versions prior to 1.1.1 contain a flaw in how the system handles certain error inputs when scripting is enabled. This vulnerability allows an attacker to use special character sequences to access sensitive information or run unauthorized commands.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users running SurrealDB versions older than 1.1.1 with scripting enabled.
Real-world impact
An attacker with scripting privileges could read private data from the system's memory or execute malicious code with the same permissions as the SurrealDB process.
Why this severity
The critical score reflects the high potential impact on the confidentiality, integrity, and availability of the system, though the attack requires specific scripting privileges and complex conditions to execute.
What to do about it
- 01Update SurrealDB to version 1.1.1 or later
NVD description
Timeline
- Jul 18, 2026 · 15d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 21, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.