VDB
Sign up
HIGH7.5

GHSA-4jv9-3563-23j3

Knex.js has a limited SQL injection vulnerability

Quick fix

GHSA-4jv9-3563-23j3 — knex: upgrade to the fixed version with the command below.

npm install knex@2.4.0

Details

Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. This vulnerability has been fixed in version 2.4.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/knex
Introduced in: 0Fixed in: 2.4.0
Fixnpm install knex@2.4.0

References