CVE-2026-69240 | Sequelize up to 6.37.3 Oracle Dialect sql-string.js escape val sql injection

SecurityVulns

A vulnerability was found in Sequelize up to 6.37.3. It has been rated as critical. Impacted is the function escape of the file sql-string.js of the component Oracle Dialect. Performing a manipulation of the argument val results in sql injection.

This vulnerability is known as CVE-2026-69240. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More