CVE-2026-69240 | Sequelize up to 6.37.3 Oracle Dialect sql-string.js escape val sql injection
A vulnerability was found in Sequelize up to 6.37.3. It has been rated as critical. Impacted is the function escape of the file sql-string.js of the component Oracle Dialect. Performing a manipulation of the argument val results in sql injection.
This vulnerability is known as CVE-2026-69240. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More