SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers with scripting privileges can supply format string sequences in error inputs to read arbitrary memory or execute code with SurrealDB process privileges.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
SurrealDB versions before 1.1.1 contain a format string vulnerability in the rquickjs Exception::throw_type function that can be exploited when scripting is enabled. An attacker with scripting privileges can inject format string sequences into error inputs, allowing them to read arbitrary memory locations or execute arbitrary code with the privileges of the SurrealDB process. This vulnerability is particularly concerning for organizations using SurrealDB as a backend database with scripting features enabled, as it provides a direct path to code execution for authenticated users or attackers who have gained scripting access through other means. The CVSS score of 8.5 reflects the high severity—combining network accessibility potential with significant impact on confidentiality and integrity.
Detecting exploitation of this vulnerability requires understanding the attack flow: an attacker must craft malicious error messages containing format string payloads (like %x, %s, or %n sequences) to trigger the vulnerable function. While this CVE maps to CWE-134 (Use of Externally-Controlled Format String), Casky's security skills—powered by Claude's extended reasoning capabilities—would identify the behavioral patterns associated with format string attacks by analyzing process memory access anomalies, unexpected code execution following error handling routines, and suspicious input patterns in scripting contexts. Practitioners using Casky would observe findings related to unusual format string patterns in application logs, unexpected memory reads or writes initiated from the database layer, and privilege escalation attempts following scripting operations. Organizations should immediately upgrade to SurrealDB 1.1.1 or later and restrict scripting privileges to trusted users only.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2024-58366. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation