VDB
Sign up
MEDIUM

GHSA-x2jc-pwfj-h9p3

SQL Injection in sequelize

Quick fix

GHSA-x2jc-pwfj-h9p3 — sequelize: upgrade to the fixed version with the command below.

npm install sequelize@1.7.0

Details

Affected versions of `sequelize` use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.

## Recommendation

Update to version 1.7.0-alpha3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sequelize
Introduced in: 0Fixed in: 1.7.0
Fixnpm install sequelize@1.7.0

References