6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether typeorm is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.7
CVE-2026-73651
TypeORM: migration:generate template-literal code injection
MEDIUM 5.9
GHSA-9ggv-8w38-r7pm
TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
MEDIUM 6.5
CVE-2025-60542
TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
CRITICAL 9.8
GHSA-w7q7-vjp8-7jv4
SQL Injection in typeorm
CRITICAL 9.8
CVE-2022-33171
SQL injection in typeORM
CRITICAL 9.8
CVE-2020-8158
TypeORM vulnerable to MAID and Prototype Pollution
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes