Vulnerability Description
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mikro-Orm | Mikroorm | < 6.6.10 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-34220?
CVE-2026-34220 is a vulnerability with a CVSS score of 9.8 (CRITICAL). MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted...
How severe is CVE-2026-34220?
CVE-2026-34220 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-34220?
Check the references section above for vendor advisories and patch information. Affected products include: Mikro-Orm Mikroorm.