MEDIUM
GHSA-x2jc-pwfj-h9p3
SQL Injection in sequelize
Quick fix
GHSA-x2jc-pwfj-h9p3 — sequelize: upgrade to the fixed version with the command below.
npm install sequelize@1.7.0Details
Affected versions of `sequelize` use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.
## Recommendation
Update to version 1.7.0-alpha3 or later.
Are you affected?
Enter the version of the package you're using.