Product
TypeORM is vulnerable to SQL injection via the SelectQueryBuilder.distinctOn method due to improper input validation and escaping, allowing for unauthorized data exfiltration through injected subqueries.