Vulnerabilities/

Veramo is Vulnerable to SQL Injection in Veramo Data Store ORM

Severity:
Medium

Description

An SQL injection vulnerability exists in the @veramo/data-store package that allows any authenticated user to execute arbitrary SQL queries against the database. The vulnerability is caused by insufficient validation of the column parameter in the order array of query requests.

Recommendation

Update the @veramo/data-store package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@veramo/data-store
Anything's wrong? Let us know Last updated on January 16, 2026