Affected versions contain multiple safe APIs that can trigger undefined behavior:
Array<T>::index can perform an out-of-bounds read.String::get_length can perform an out-of-bounds read.String::append_character can perform an invalid write.String::to_c_string can perform an out-of-bounds write.These issues were reproduced against scaly 0.0.37 under Miri. The crate is unmaintained.
Exploitability
AV:NAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:NVA:HSubsequent System
SC:NSI:NSA:N8.7/CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N