Critical SQL Injection Vulnerability in Sequelize ORM Affects Oracle Users

Critical SQL Injection Vulnerability in Sequelize ORM Affects Oracle Users

First seen 4 Aug 2026, 18:12 UTC Feedlycve.akaoma.comwww.tenable.comdev.towww.thehackerwire.com 94% similarity 72.9

Article Content

Browse articles
ThreatCluster

CVE-2026-69240 is a critical SQL injection vulnerability affecting Sequelize ORM when configured for Oracle databases. The flaw, rated 9.8 on the CVSS scale, allows attackers to inject arbitrary SQL expressions through specially crafted input starting with 'TO_TIMESTAMP' or 'TO_DATE'. The escape function in sql-string.js fails to properly escape quotes in these cases, enabling potential exploitation. The vulnerability has been addressed in version 6.37.4, which users are urged to upgrade to immediately. No public proof-of-concept exploits have been reported, and there are no confirmed cases of exploitation in the wild. The vulnerability was first published on August 3, 2026, and has significant implications for affected users. Security advisories have been released, emphasizing the urgency of the situation.

Key Points: • CVE-2026-69240 is a critical SQL injection vulnerability rated 9.8 on CVSS. • The flaw affects Sequelize ORM when configured for Oracle databases, allowing SQL injection. • Users are urged to upgrade to version 6.37.4 to mitigate the risk of exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-03
CVE-2026-69240 published
CVE-2026-69240 was officially published, detailing a critical SQL injection vulnerability in Sequelize ORM.
Feedly
2026-08-04
Security advisory released
Security advisories were issued, urging immediate upgrades to version 6.37.4 to address the vulnerability.
cve.akaoma.com

Community

Browse all →

Tracked Entities in This Story