{"id":"GHSA-m9jw-237r-gvfv","summary":"SQL Injection in sequelize","details":"Affected versions of `sequelize` are vulnerable to SQL Injection. The function `sequelize.json()` incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query.  Exploitation example:  \n\n```js\nreturn User.findAll({\n  where: this.sequelize.json(\"data.id')) AS DECIMAL) = 1 DELETE YOLO INJECTIONS; -- \", 1)\n});\n```\n\n\n## Recommendation\n\nIf you are using `sequelize` 5.x, upgrade to version 5.15.1 or later.\nIf you are using `sequelize` 4.x, upgrade to version 4.44.3 or later.","aliases":["CVE-2019-10752"],"modified":"2024-11-13T01:11:52.332934Z","published":"2019-10-25T19:43:16Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-10-22T15:53:58Z","nvd_published_at":null,"cwe_ids":["CWE-89"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10752"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/pull/11329"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/commit/9bd0bc1,"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751,"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1146"}],"affected":[{"package":{"name":"sequelize","ecosystem":"npm","purl":"pkg:npm/sequelize"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.44.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-m9jw-237r-gvfv/GHSA-m9jw-237r-gvfv.json"}},{"package":{"name":"sequelize","ecosystem":"npm","purl":"pkg:npm/sequelize"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.15.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/10/GHSA-m9jw-237r-gvfv/GHSA-m9jw-237r-gvfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}