Description
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
Recommendation
Update the typeorm package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.3.26
- Patched version(s): 0.3.26
References
Could your website be exposed too?
SmartScanner can check your website for TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Flowise Vulnerable to SQL Injection via `tableName` Parameter - CVE-2025-29189
- Angular SSR is vulnerable to SSRF and Header Injection via request handling pipeline - CVE-2026-27739
- OneUptime ClickHouse vulnerable to SQL Injection via unvalidated column identifiers in sort, select, and groupBy paramet - CVE-2026-33142
- Matrix-appservice-irc vulnerable to sql injection via roomIds argument - CVE-2022-3971


