{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/node-sql-query-0.1.25-0.1.26-0.1.27-0.1.28/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19351"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["node-sql-query (0.1.25, 0.1.26, 0.1.27, 0.1.28)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["dresende"],"content_html":"\u003cp\u003eThe node-sql-query library (versions 0.1.25 through 0.1.28) contains a critical SQL injection vulnerability within its 'SelectQuery.from' and 'SelectQuery.build' functions in 'lib/Select.js'. The flaw resides in the library's Request Parameter Handler, which fails to properly sanitize input before incorporating it into SQL queries. This allows a remote, unauthenticated attacker to manipulate request parameters to inject malicious SQL syntax into database operations. The vulnerability has been publicly disclosed with a proof-of-concept exploit, posing a significant risk to applications relying on this library for database interaction. Developers are strongly encouraged to upgrade to version 0.1.29, which addresses the issue via the patch '3414c42f6de89826fa1f5f36f6139d1e6552778e'.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability enables attackers to perform unauthorized database operations, including data exfiltration, modification, or deletion. Depending on the database permissions and application configuration, this could lead to full database compromise, unauthorized access to sensitive user data, and potential remote code execution on the underlying database server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'node-sql-query' dependency to version 0.1.29 or higher across all development, staging, and production environments.\u003c/li\u003e\n\u003cli\u003eReview database logs for suspicious query patterns characterized by unexpected union selects, comment characters, or tautologies originating from the application layer.\u003c/li\u003e\n\u003cli\u003eImplement parameterized queries or an object-relational mapping (ORM) layer that enforces strict input validation for all database interactions to mitigate the impact of similar SQL injection vulnerabilities.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-09T13:45:36Z","date_published":"2026-08-09T13:45:36Z","id":"https://feed.craftedsignal.io/briefs/2026-08-node-sql-query-sqli/","summary":"A SQL injection vulnerability in the SelectQuery component of the node-sql-query library allows remote attackers to execute arbitrary SQL commands via manipulated request parameters.","title":"SQL Injection Vulnerability in node-sql-query","url":"https://feed.craftedsignal.io/briefs/2026-08-node-sql-query-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Node-Sql-Query (0.1.25, 0.1.26, 0.1.27, 0.1.28)","version":"https://jsonfeed.org/version/1.1"}