{"id":"GHSA-x2jc-pwfj-h9p3","summary":"SQL Injection in sequelize","details":"Affected versions of `sequelize` use MySQL's backslash-based escape syntax when connecting to SQLite, despite the fact that SQLite uses PostgreSQL's escape syntax, which can result in a SQL Injection vulnerability.\n\n\n## Recommendation\n\nUpdate to version 1.7.0-alpha3 or later.","aliases":["CVE-2016-10554"],"modified":"2023-11-08T03:58:12.264608Z","published":"2019-02-18T23:54:28Z","database_specific":{"github_reviewed_at":"2020-06-16T22:01:45Z","nvd_published_at":null,"cwe_ids":["CWE-89"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10554"},{"type":"WEB","url":"https://github.com/sequelize/sequelize/commit/c876192aa6ce1f67e22b26a4d175b8478615f42d"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x2jc-pwfj-h9p3"},{"type":"WEB","url":"https://www.npmjs.com/advisories/113"}],"affected":[{"package":{"name":"sequelize","ecosystem":"npm","purl":"pkg:npm/sequelize"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.7.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-x2jc-pwfj-h9p3/GHSA-x2jc-pwfj-h9p3.json","last_known_affected_version_range":"\u003c= 1.7.0-alpha2"}}],"schema_version":"1.9.0"}