CVE-2026-19351
dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
| CWE | CWE-89 CWE-74 |
| Vendor | dresende |
| Product | node-sql-query |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for dresende node-sql-query
Be the first to know when new high vulnerabilities affecting dresende node-sql-query are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
dresende / node-sql-query
0.1.25 0.1.26 0.1.27 0.1.28
References
vuldb.com: https://vuldb.com/vuln/387190 vuldb.com: https://vuldb.com/vuln/387190/cti vuldb.com: https://vuldb.com/cve/CVE-2026-19351 vuldb.com: https://vuldb.com/submit/865884 github.com: https://github.com/windhxy/CVE-my/issues/2 github.com: https://github.com/dresende/node-sql-query/pull/64 github.com: https://github.com/dresende/node-sql-query/commit/3414c42f6de89826fa1f5f36f6139d1e6552778e github.com: https://github.com/dresende/node-sql-query/releases/tag/v0.1.29 github.com: https://github.com/dresende/node-sql-query/
Credits
๐ windhxy (VulDB User)