CVE-2023-22578 - Sequalize - Default support for “raw attributes” when using parentheses

CVE CVE-2023-22578
Discovered by
  • Thomas Rinsma and Kevin Valk
Affected products
Product Affected Unaffected Unknown
Feathers-Sequalize Sequelize.js = Before v7.0.0-alpha.20
everything else
CVSS Base score: 10 (CRITICAL)
Problem type(s) CWE-790: Improper Filtering of Special Elements
Last modified 16 Feb 2023 10:10


Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.

