CVE-2026-19351: dresende node-sql-query Request Parameter Select.js SelectQuery.build sql injection
A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
dresende node-sql-queryto a version that resolves this vulnerability.Fixed in 0.1.29Patch 3414c42f6de89826fa1f5f36f6139d1e6552778e
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19351?
The severity of CVE-2026-19351 is classified as high with a score of 7.3.
How do I fix CVE-2026-19351?
To fix CVE-2026-19351, update the dresende node-sql-query library to a version that is not affected by this vulnerability.
What type of vulnerability is CVE-2026-19351?
CVE-2026-19351 is a SQL Injection vulnerability found in the node-sql-query library.
Which versions of the library are affected by CVE-2026-19351?
The affected versions of the dresende node-sql-query library are 0.1.25, 0.1.26, 0.1.27, and 0.1.28.
What impact does CVE-2026-19351 have on applications?
CVE-2026-19351 can lead to unauthorized SQL query manipulation, potentially compromising the database integrity.