Skip to main content
CRITICAL

CVE-2023-25813

CVSS v3

9.8

CRITICAL

EPSS Score

3.9 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.

Technical details

Published
2023-02-22

Frequently asked questions

What is CVE-2023-25813?

Sequelize is a Node.js ORM tool. In versions prior to 6.19.1 a SQL injection exploit exists related to replacements. Parameters which are passed through replacements are not properly escaped which can lead to arbitrary SQL injection depending on the specific queries in use. The issue has been fixed in Sequelize 6.19.1. Users are advised to upgrade. Users unable to upgrade should not use the `replacements` and the `where` option in the same query.

Is CVE-2023-25813 actively exploited?

Active exploitation of CVE-2023-25813 has not been confirmed. The EPSS score is 3.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-25813?

CVE-2023-25813 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-25813 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key