VDB
Sign up
CRITICAL9.8

GHSA-m9jw-237r-gvfv

SQL Injection in sequelize

Quick fix

GHSA-m9jw-237r-gvfv — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@4.44.3

Details

Affected versions of `sequelize` are vulnerable to SQL Injection. The function `sequelize.json()` incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query. Exploitation example:

```js return User.findAll({ where: this.sequelize.json("data.id')) AS DECIMAL) = 1 DELETE YOLO INJECTIONS; -- ", 1) }); ```

## Recommendation

If you are using `sequelize` 5.x, upgrade to version 5.15.1 or later. If you are using `sequelize` 4.x, upgrade to version 4.44.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 4.44.3
Fixnpm install sequelize@4.44.3
npm/sequelize
Introduced in: 5.0.0Fixed in: 5.15.1
Fixnpm install sequelize@5.15.1

References