HIGH
GHSA-98pq-pmw9-4gpm
SQL Injection in sequelize
Quick fix
GHSA-98pq-pmw9-4gpm — sequelize: upgrade to the fixed version with the command below.
npm install sequelize@3.17.0Details
Affected versions of `sequelize` are vulnerable to SQL Injection in locations where user input is passed into the `limit` or `order` parameters of `sequelize` query calls, such as `findOne` or `findAll`.
## Recommendation
Update to version 3.17.0 or later.
Are you affected?
Enter the version of the package you're using.