CVE-2026-76848 | TypeORM up to 1.1.0 SelectQueryBuilder SelectQueryBuilder.ts createSelectDistinctExpression distinctOn sql injection

SecurityVulns

A vulnerability, which was classified as critical, was found in TypeORM up to 1.1.0. This issue affects the function createSelectDistinctExpression of the file src/query-builder/SelectQueryBuilder.ts of the component SelectQueryBuilder. The manipulation of the argument distinctOn results in sql injection.

This vulnerability is reported as CVE-2026-76848. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More