{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-69240/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Sequelize (\u003c 6.37.4)"],"_cs_severities":["critical"],"_cs_tags":["web-vulnerability","sqli","npm","cve-2026-69240"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eSequelize, a widely used ORM for Node.js, contains a critical SQL injection vulnerability (CVE-2026-69240) affecting the library when configured to use the Oracle database dialect. The vulnerability stems from an insecure implementation of the \u003ccode\u003eescape\u003c/code\u003e function in \u003ccode\u003esql-string.js\u003c/code\u003e. Specifically, the function checks if an input string begins with the patterns \u003ccode\u003eTO_TIMESTAMP\u003c/code\u003e or \u003ccode\u003eTO_DATE\u003c/code\u003e and returns the input raw if these conditions are met, bypassing the standard quote-escaping logic.\u003c/p\u003e\n\u003cp\u003eThis flaw allows an attacker to inject arbitrary SQL expressions if the application uses unsanitized user input (such as URL parameters) within Sequelize query objects. Because this occurs within the ORM's own escaping logic, the vulnerability is particularly dangerous for applications relying on Sequelize to automatically sanitize database interactions. This vulnerability was addressed in Sequelize v6.37.4.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized database access, enabling attackers to perform unauthorized data exfiltration, modification, or deletion. Impact is dependent on the application's implementation and the database permissions assigned to the service account executing the SQL queries. Given the nature of SQL injection, this vulnerability poses a high risk to the confidentiality and integrity of any database connected to a vulnerable Sequelize instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Sequelize package to v6.37.4 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit applications using Sequelize to ensure that they are not accepting arbitrary query parameters directly into the \u003ccode\u003ewhere\u003c/code\u003e clause without strict type validation or schema-based input sanitization.\u003c/li\u003e\n\u003cli\u003eReview database audit logs for anomalous SQL patterns, specifically queries containing \u003ccode\u003eTO_TIMESTAMP\u003c/code\u003e or \u003ccode\u003eTO_DATE\u003c/code\u003e followed by SQL logical operators or comment delimiters (e.g., \u003ccode\u003e--\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eDeploy application-level WAF rules to detect and block URL parameters containing SQL metacharacters if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T20:47:47Z","date_published":"2026-08-03T20:47:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sequelize-sqli/","summary":"Sequelize v6.37.3 and earlier versions contain a critical SQL injection vulnerability in the Oracle dialect implementation, allowing unauthenticated attackers to bypass input sanitization and execute arbitrary SQL.","title":"SQL Injection in Sequelize Oracle Dialect","url":"https://feed.craftedsignal.io/briefs/2026-08-sequelize-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-69240","version":"https://jsonfeed.org/version/1.1"}