Vulnary
← back to the feed
Critical· 9official fix available

CVE-2024-58366

SurrealDB versions prior to 1.1.1 contain a flaw in how the system handles certain error inputs when scripting is enabled. This vulnerability allows an attacker to use special character sequences to access sensitive information or run unauthorized commands.

publishedJul 18, 2026
last modifiedJul 21, 2026
sourcesNVD
severity · cvss
9
critical · how bad it is
exploitation · epss
<1%
22th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 1, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Users running SurrealDB versions older than 1.1.1 with scripting enabled.

02

Real-world impact

An attacker with scripting privileges could read private data from the system's memory or execute malicious code with the same permissions as the SurrealDB process.

03

Why this severity

The critical score reflects the high potential impact on the confidentiality, integrity, and availability of the system, though the attack requires specific scripting privileges and complex conditions to execute.

04

What to do about it

official fix available
recommended steps
  1. 01Update SurrealDB to version 1.1.1 or later

NVD description

05

Timeline

  1. Jul 18, 2026 · 15d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 21, 2026 · 12d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityHigh
Attack requirementsPresent
Privileges requiredLow
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
CVE-2024-58366: SurrealDB versions prior to 1.1.1 contain a flaw in how the system han · Vulnary