HIGH 8.5 npm

Payload has an SQL Injection via Query Handling

GHSA-7xxh-373w-35vg · CVE-2026-34747

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Certain request inputs were not properly validated. An attacker could craft requests that influence SQL query execution, potentially exposing or modifying data in collections.

Patches

This issue has been fixed in v3.79.1 and later. Query input validation has been hardened.

Upgrade to v3.79.1 or later.

Workarounds

Until developers can upgrade:

  • Limit access to endpoints that accept dynamic query inputs to trusted users only.
  • Validate or sanitize input from untrusted clients before sending it to query endpoints.

Ready to move

Start Securing

Free, no credit card | First findings in minutes