Critical SQL Injection Vulnerability in Sequelize ORM Affects Oracle Users
ID: d320ec88-901b-5f1e-a2f6-dd412a274aa7
STIX ID: report--d320ec88-901b-5f1e-a2f6-dd412a274aa7
Feed Name: ThreatCluster
Threat Score
CVE-2026-69240 is a critical SQL injection vulnerability (CVSS 9.8) affecting Sequelize ORM when used with Oracle databases: the escape function in sql-string.js fails to properly escape inputs starting with 'TO_TIMESTAMP' or 'TO_DATE', enabling arbitrary SQL injection. The issue is fixed in Sequelize 6.37.4 and users are urged to upgrade immediately; no public proof-of-concept or confirmed exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
