Back

CRITICAL

SurrealDB before 1.1.1 Format String via Scripting Functions

Published Jul 18, 2026

Description

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 18, 2026
Updated Jul 28, 2026
Reserved Jul 18, 2026
CISA Vulnrichment
Updated Jul 20, 2026
NVD
Status Analyzed
Modified Aug 13, 2026
Red Hat
Severity n/a
Public date n/a