๐Ÿ” CVE Alert

CVE-2026-19351

HIGH 7.3

dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.

CWE CWE-89 CWE-74
Vendor dresende
Product node-sql-query
Published Aug 9, 2026
Stay Ahead of the Next One

Get instant alerts for dresende node-sql-query

Be the first to know when new high vulnerabilities affecting dresende node-sql-query are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

dresende / node-sql-query
0.1.25 0.1.26 0.1.27 0.1.28

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/387190 vuldb.com: https://vuldb.com/vuln/387190/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19351 vuldb.com: https://vuldb.com/submit/865884 github.com: https://github.com/windhxy/CVE-my/issues/2 github.com: https://github.com/dresende/node-sql-query/pull/64 github.com: https://github.com/dresende/node-sql-query/commit/3414c42f6de89826fa1f5f36f6139d1e6552778e github.com: https://github.com/dresende/node-sql-query/releases/tag/v0.1.29 github.com: https://github.com/dresende/node-sql-query/

Credits

๐Ÿ” windhxy (VulDB User)