VDB
Sign up

package

npm/kysely

pkg:npm/kysely

HIGH8.1npm
GHSA-8cpq-38p9-67gx· CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Modified: 9/10/2026