{"id":"GHSA-9c2p-jw8p-f84v","summary":"SQL Injection in sequelize","details":"Affected versions of `sequelize` cast arrays to strings and fail to properly escape the resulting SQL statement, resulting in a SQL injection vulnerability.\n\n\n## Proof of Concept\nIn Postgres, SQLite, and Microsoft SQL Server there is an issue where arrays are treated as strings and improperly escaped.\n\nExample Query:\n```\ndatabase.query('SELECT * FROM TestTable WHERE Name IN (:names)', {\n  replacements: {\n    names: directCopyOfUserInput\n  }\n});\n```\n\nIf the user inputs the value of `:names` as:\n```\n[\"test\", \"'); DELETE TestTable WHERE Id = 1 --')\"]\n```\n\nThe resulting SQL statement will be:\n```sql\nSELECT Id FROM Table WHERE Name IN ('test', '\\'); DELETE TestTable WHERE Id = 1 --')\n```\nAs the backslash has no special meaning in PostgreSQL, MSSQL, or SQLite, the statement will delete the record in TestTable with an Id of 1.\n\n\n## Recommendation\n\nUpdate to version 3.20.0 or later.","aliases":["CVE-2016-10556"],"modified":"2023-11-08T03:58:12.386286Z","published":"2019-02-18T23:54:24Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:28:12Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10556"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/issues/5671"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/commit/23952a2b020cc3571f090e67dae7feb084e1be71"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/commits/v3.20.0?after=62e4dacb28a779a190a3e042b971dcd8c7926e49+34&branch=v3.20.0&qualified_name=refs%2Ftags%2Fv3.20.0"}],"affected":[{"package":{"name":"sequelize","ecosystem":"npm","purl":"pkg:npm/sequelize"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.20.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 3.19.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-9c2p-jw8p-f84v/GHSA-9c2p-jw8p-f84v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}