Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-19351: dresende node-sql-query SQL Injection via Request Parameter

CVE-2026-19351 · published 26 days ago
Summary

A security issue in dresende node-sql-query allows attackers to inject malicious SQL code. This could lead to unauthorized data access or manipulation. To fix this, update to version 0.1.29.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
dresende node-sql-query 0.1.25
Original advisory text
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of t...
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
Severity
5.5 Medium
CVSS 2.0: 7.5 (NVD)
CVSS 3.1: 7.3 (NVD)
CVSS 4.0: 5.5 (NVD)
CVSS 4.0: 8.4 (OSV)
Exploitation
EPSS <1%
Type
CWE-74Injection
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated3 Sep 2026
First seen9 Aug 2026
Sources
CVE-2026-19351 · MITRE
Monitor software like this
Free during beta