MEDIUM
GHSA-fvq6-55gv-jx9f
SQL Injection in mysql
Quick fix
GHSA-fvq6-55gv-jx9f — mysql: upgrade to the fixed version with the command below.
npm install mysql@2.0.0-alpha8Details
Versions of `mysql` prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in the `mysql.escape()` function, which does not properly escape object keys.
## Recommendation
Update to version 2.0.0-alpha8 or later.
Are you affected?
Enter the version of the package you're using.