CVE-2019-10748: Sequelizejs Sequelize
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
Affected products
- Sequelizejs Sequelize: from 3.0.0, before 3.35.1 (fixed in 3.35.1); from 4.0.0, before 4.44.3 (fixed in 4.44.3); from 5.0.0, up to and including 5.8.11
Published 2019-10-29. Last modified 2026-06-17.