UNKNOWN npm

NoSQL Injection in sequelize

GHSA-wfp9-vr4j-f49j

Published · Modified

Description

Versions of sequelize prior to 4.12.0 are vulnerable to NoSQL Injection. Query operators such as $gt are not properly sanitized and may allow an attacker to alter data queries, leading to NoSQL Injection.

Recommendation

Upgrade to version 4.12.0 or later

Ready to move

Start Securing

Free, no credit card | First findings in minutes