CRITICAL 9.8 npm

SQL Injection in sequelize

GHSA-2598-2f59-rmhq · CVE-2019-10749 · SNYK-JS-SEQUELIZE-450222

Published · Modified

Description

Versions of sequelize prior to 3.35.1 are vulnerable to SQL Injection. The package fails to sanitize JSON path keys in the Postgres dialect, which may allow attackers to inject SQL statements and execute arbitrary SQL queries.

Recommendation

Upgrade to version 3.35.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes