Description
Versions of typeorm before 0.1.15 are vulnerable to SQL Injection. Field names are not properly validated allowing attackers to inject SQL statements and execute arbitrary SQL queries.
Recommendation
Update the typeorm package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.1.15
- Patched version(s): 0.1.15
References
Could your website be exposed too?
SmartScanner can check your website for SQL Injection in typeorm - typeorm and gives you actionable findings to investigate.
Start a free scanRelated Issues
- TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB) - Vulnerability
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- Failure to sanitize quotes which can lead to sql injection in squel - Vulnerability
- Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated February 11, 2026


