GHSA-jqv5-7xpx-qj74
sqlite vulnerable to code execution due to Object coercion
Quick fix
GHSA-jqv5-7xpx-qj74 — sqlite3: upgrade to the fixed version with the command below.
npm install sqlite3@5.1.5Details
### Impact
Due to the underlying implementation of `.ToString()`, it's possible to execute arbitrary JavaScript, or to achieve a denial-of-service, if a binding parameter is a crafted Object.
Users of `sqlite3` v5.0.0 - v5.1.4 are affected by this.
### Patches
Fixed in v5.1.5. All users are recommended to upgrade to v5.1.5 or later.
### Workarounds
* Ensure there is sufficient sanitization in the parent application to protect against invalid values being supplied to binding parameters.
### References
* Commit: https://github.com/TryGhost/node-sqlite3/commit/edb1934dd222ae55632e120d8f64552d5191c781
### For more information
If you have any questions or comments about this advisory:
* Email us at [security@ghost.org](mailto:security@ghost.org)
Credits: Dave McDaniel of Cisco Talos
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/TryGhost/node-sqlite3/security/advisories/GHSA-jqv5-7xpx-qj74[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-43441[ADVISORY]
- https://github.com/TryGhost/node-sqlite3/commit/edb1934dd222ae55632e120d8f64552d5191c781[WEB]
- https://github.com/TryGhost/node-sqlite3[PACKAGE]
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1645[WEB]