Vulnerabilities/

pg-promise SQL Injection vulnerability

Severity:
Medium

Description

pg-promise before 11.5.5 is vulnerable to SQL Injection due to improper handling of negative numbers.

Recommendation

Update the pg-promise package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
pg-promise
Anything's wrong? Let us know Last updated on June 18, 2025

This issue is available in SmartScanner Professional

See Pricing