THREAT OPS › Threat News › [NVD] CVE-2026-19351 (HIGH 7.3) — A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql in
[NVD] CVE-2026-19351 (HIGH 7.3) — A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql in
CVE-2026-19351 CVSS: 7.3 HIGH Published: 2026-08-09T12:16:29.457
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotel
Indicators of compromise
- 3414c42f6de89826fa1f5f36f6139d1e6552778esha1
- CVE-2026-19351cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-19351