Количество 4
Количество 4
CVE-2026-30951
Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.
CVE-2026-30951
Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.
GHSA-6457-6jrx-69cr
Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type
BDU:2026-04971
Уязвимость функции _traverseJSON () ORM-библиотеки Sequelize, позволяющая нарушителю выполнить произвольный SQL-код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-30951 Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
CVE-2026-30951 Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-6457-6jrx-69cr Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
BDU:2026-04971 Уязвимость функции _traverseJSON () ORM-библиотеки Sequelize, позволяющая нарушителю выполнить произвольный SQL-код | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу