VDB
Sign up
CRITICAL9.8

GHSA-58v4-qwx5-7f59

SQL Injection in knex

Quick fix

GHSA-58v4-qwx5-7f59 — knex: upgrade to the fixed version with the command below.

npm install knex@0.19.5

Details

knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/knex
Introduced in: 0Fixed in: 0.19.5
Fixnpm install knex@0.19.5

References