CVE-2025-60542 PUBLISHED CVSS 6.5 MEDIUM

SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.

EPSS 0.06% · 17.7th percentile

Risk Scores

CVSS v3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
0.06%
17.7th percentile

Affected Products

VendorProductVersions
n/an/an/a
npmtypeorm0

Timeline

References

Open in Interactive Console →