Vulnerability Description
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/dresende/node-sql-query/
- https://github.com/dresende/node-sql-query/commit/3414c42f6de89826fa1f5f36f6139d
- https://github.com/dresende/node-sql-query/pull/64
- https://github.com/dresende/node-sql-query/releases/tag/v0.1.29
- https://github.com/windhxy/CVE-my/issues/2
- https://vuldb.com/cve/CVE-2026-19351
- https://vuldb.com/submit/865884
- https://vuldb.com/vuln/387190
- https://vuldb.com/vuln/387190/cti
- https://vuldb.com/submit/865884
FAQ
What is CVE-2026-19351?
CVE-2026-19351 is a vulnerability with a CVSS score of 7.3 (HIGH). A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the ...
How severe is CVE-2026-19351?
CVE-2026-19351 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19351?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.