VDB
Sign up
HIGH

GHSA-wfp9-vr4j-f49j

NoSQL Injection in sequelize

Quick fix

GHSA-wfp9-vr4j-f49j — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@4.12.0

Details

Versions of `sequelize` prior to 4.12.0 are vulnerable to NoSQL Injection. Query operators such as `$gt` are not properly sanitized and may allow an attacker to alter data queries, leading to NoSQL Injection.

## Recommendation

Upgrade to version 4.12.0 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 4.12.0
Fixnpm install sequelize@4.12.0

References