Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30951

Опубликовано: 10 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS ) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.

A flaw was found in Sequelize, a Node.js Object-Relational Mapper (ORM) tool. A remote attacker can exploit a SQL injection vulnerability by manipulating JSON object keys during JSON/JSONB where clause processing. This allows for the injection of arbitrary SQL commands due to the improper handling of cast types. The primary consequence is the potential for unauthorized data exfiltration from any database table.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-pccsAffected
Red Hat Enterprise Linux 10linux-sgxNot affected
Red Hat Enterprise Linux 9linux-sgxNot affected
Red Hat Satellite 6.18satellite/iop-remediations-rhel9FixedRHSA-2026:849816.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-89
https://bugzilla.redhat.com/show_bug.cgi?id=2446250sequelize: Sequelize: Data exfiltration via SQL injection in JSON/JSONB where clause processing

EPSS

Процентиль: 35%
0.00422
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.

CVSS3: 7.5
github
5 месяцев назад

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость функции _traverseJSON () ORM-библиотеки Sequelize, позволяющая нарушителю выполнить произвольный SQL-код

EPSS

Процентиль: 35%
0.00422
Низкий

7.5 High

CVSS3