VDB
CISA-2025-60542
CISA-2025-60542
PUBLISHED
CVSS 6.5 MEDIUM
Reported by mitre · Published October 29, 2025
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, * |
Timeline
- Oct 29, 2025 CVE Published
- Oct 30, 2025 CVE Updated