VDB
Sign up
CRITICAL9.8

GHSA-w7q7-vjp8-7jv4

SQL Injection in typeorm

Quick fix

GHSA-w7q7-vjp8-7jv4 — typeorm: upgrade to the fixed version with the command below.

npm install typeorm@0.1.15

Details

Versions of `typeorm` before 0.1.15 are vulnerable to SQL Injection. Field names are not properly validated allowing attackers to inject SQL statements and execute arbitrary SQL queries.

## Recommendation

Upgrade to version 0.1.15

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/typeorm
Introduced in: 0Fixed in: 0.1.15
Fixnpm install typeorm@0.1.15

References