VDB
Sign up
CRITICAL9.8

GHSA-5hq7-j5wq-p227

feathers-sequelize vulnerable to SQL injection due to improper parameter filtering

Quick fix

GHSA-5hq7-j5wq-p227 — feathers-sequelize: upgrade to the fixed version with the command below.

npm install feathers-sequelize@6.3.4

Details

feathers-sequelize is vulnerable to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/feathers-sequelize
Introduced in: 6.0.0Fixed in: 6.3.4
Fixnpm install feathers-sequelize@6.3.4

References