VDB
Sign up
CRITICAL9.8

GHSA-5v9h-q3gj-c32x

SQL Injection via GeoJSON in sequelize

Quick fix

GHSA-5v9h-q3gj-c32x — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@3.23.6

Details

Affected versions of `sequelize` are vulnerable to SQL Injection in Models that have fields with the `GEOMETRY` DataType. This vulnerability occurs because single quotes in document values are not escaped for GeoJSON documents using `ST_GeomFromGeoJSON`, and MySQL GeoJSON documents using `GeomFromText`.

## Recommendation

Update to version 3.23.6 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 3.4.0Fixed in: 3.23.6
Fixnpm install sequelize@3.23.6

References