Description
All versions of squel are vulnerable to sql injection.
The squel package does not properly escape user provided input when provided using the setFields method. This could lead to sql injection if the query was then executed.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 5.13.0
References
Could your website be exposed too?
SmartScanner can check your website for Failure to sanitize quotes which can lead to sql injection in squel and gives you actionable findings to investigate.
Start a free scanRelated Issues
- beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) - CVE-2026-26226
- @langchain/community SQL Injection vulnerability - CVE-2024-7042
- Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM - Vulnerability
- Better Call routing bug can lead to Cache Deception - Vulnerability


