Логотип exploitDog
bind:CVE-2026-30951
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-30951

Количество 3

Количество 3

redhat логотип

CVE-2026-30951

17 дней назад

A flaw was found in Sequelize, a Node.js Object-Relational Mapper (ORM) tool. A remote attacker can exploit a SQL injection vulnerability by manipulating JSON object keys during JSON/JSONB where clause processing. This allows for the injection of arbitrary SQL commands due to the improper handling of cast types. The primary consequence is the potential for unauthorized data exfiltration from any database table.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-30951

17 дней назад

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6457-6jrx-69cr

17 дней назад

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-30951

A flaw was found in Sequelize, a Node.js Object-Relational Mapper (ORM) tool. A remote attacker can exploit a SQL injection vulnerability by manipulating JSON object keys during JSON/JSONB where clause processing. This allows for the injection of arbitrary SQL commands due to the improper handling of cast types. The primary consequence is the potential for unauthorized data exfiltration from any database table.

CVSS3: 7.5
0%
Низкий
17 дней назад
nvd логотип
CVE-2026-30951

Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function splits JSON path keys on :: to extract a cast type, which is interpolated raw into CAST(... AS <type>) SQL. An attacker who controls JSON object keys can inject arbitrary SQL and exfiltrate data from any table. This vulnerability is fixed in 6.37.8.

CVSS3: 7.5
0%
Низкий
17 дней назад
github логотип
GHSA-6457-6jrx-69cr

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

CVSS3: 7.5
0%
Низкий
17 дней назад

Уязвимостей на страницу