Vulnerabilities/

Drizzle ORM has SQL injection via improperly escaped SQL identifiers

Severity:
High

Description

Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks.

Recommendation

Update the drizzle-orm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
drizzle-orm
Anything's wrong? Let us know Last updated on April 08, 2026