Sequelize all versions prior to 3.35.1, 4.44.3, and 5.8.11 are vulnerable to SQL Injection due to JSON path keys not being properly escaped for the MySQL/MariaDB dialects.
| Software | From | Fixed in |
|---|---|---|
| sequelizejs / sequelize | 4.0.0 | 4.44.3 |
| sequelizejs / sequelize | 3.0.0 | 3.35.1 |
| sequelizejs / sequelize | 5.0.0 | 5.8.11.x |
sequelize
|
- | 3.35.1 |
sequelize
|
4.0.0 | 4.44.3 |
sequelize
|
5.0.0 | 5.8.11 |