VDB
Sign up
HIGH7.5

GHSA-2777-2vq8-c4v4

SQL Injection in sequelize

Quick fix

GHSA-2777-2vq8-c4v4 — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@5.3.0

Details

Versions of `sequelize` prior to 5.3.0 (excluding v3 and v4) are vulnerable to SQL Injection. PostgreSQL option`standard_conforming_strings` is not set to `on` by default, which may allow attackers to inject SQL statements due to poor handling of backslashes in string literals.

## Recommendation

Upgrade to version 5.3.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 5.0.0Fixed in: 5.3.0
Fixnpm install sequelize@5.3.0

References