CVE-2019-11069: Sequelizejs Sequelize

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Sequelize version 5 before 5.3.0 does not properly ensure that standard conforming strings are used.

Affected products

  • Sequelizejs Sequelize: from 5.0.0, before 5.3.0 (fixed in 5.3.0)

Published 2019-04-10. Last modified 2026-06-17.