HIGH 8.5 npm
Payload has an SQL Injection via Query Handling
GHSA-7xxh-373w-35vg · CVE-2026-34747
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections.
Patches
This issue has been fixed in v3.79.1 and later. Query input validation has been hardened.
Upgrade to v3.79.1 or later.
Workarounds
Until developers can upgrade:
- Limit access to endpoints that accept dynamic query inputs to trusted users only.
- Validate or sanitize input from untrusted clients before sending it to query endpoints.
Ready to move
Start Securing
Free, no credit card | First findings in minutes