CVE-2019-10757: Knexjs Knex
Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.
knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious query to the host DB.
Affected products
- Knexjs Knex: before 0.19.5 (fixed in 0.19.5)
Published 2019-10-08. Last modified 2026-06-17.