<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 07:22:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-226392</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-226392</link>
      <description>EUVD-2026-226392</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-226392</guid>
    </item>
    <item>
      <title>fkie_cve-2023-22578</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-22578</link>
      <description>&lt;p&gt;Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Due to improper artibute filtering in the sequalize js library, can a attacker peform SQL injections.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-22578</guid>
    </item>
    <item>
      <title>GHSA-f598-mfpv-gmfx — Sequelize - Default support for “raw attributes” when using parentheses</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f598-mfpv-gmfx</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @sequelize/core, npm: sequelize&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Sequelize 6.28.2 and prior has a dangerous feature where using parentheses in the attribute option would make Sequelize use the string as-is in the SQL&lt;/p&gt;
&lt;p&gt;```ts
User.findAll({
  attributes: [
    [&amp;#39;count(id)&amp;#39;, &amp;#39;count&amp;#39;]
  ]
});
```&lt;/p&gt;
&lt;p&gt;Produced&lt;/p&gt;
&lt;p&gt;```sql
SELECT count(id) AS &amp;#34;count&amp;#34; FROM &amp;#34;users&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This feature was deprecated in Sequelize 5, and using it prints a deprecation warning.&lt;/p&gt;
&lt;p&gt;This issue has been patched in [`@sequelize/core@7.0.0.alpha-20`](https://github.com/sequelize/sequelize/pull/15374) and [`sequelize@6.29.0`](https://github.com/sequelize/sequelize/pull/15710).&lt;/p&gt;
&lt;p&gt;In Sequelize 7, it now produces the following:&lt;/p&gt;
&lt;p&gt;```sql
SELECT &amp;#34;count(id)&amp;#34; AS &amp;#34;count&amp;#34; FROM &amp;#34;users&amp;#34;
```&lt;/p&gt;
&lt;p&gt;In Sequelize 6, it throws an error explaining that we had to introduce a breaking change, and requires the user to explicitly opt-in to either the Sequelize 7 behavior (always escape) or the Sequelize 5 behavior (inline attributes that include `()` without escaping). See https://github.com/sequelize/sequelize/pull/15710 for more information.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Do not use user-provided content to build your list or attributes. If you do, make sure that attribute in question actually exists on your model by checking that it exists in the `rawAttributes` property of your model first.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;A discussion thread about this issue is open at https://github.com/sequelize/sequelize/discussions/15694
CVE: CVE-2023-22578&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @sequelize/core, npm: sequelize&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;Sequelize 6.28.2 and prior has a dangerous feature where using parentheses in the attribute option would make Sequelize use the string as-is in the SQL&lt;/p&gt;
&lt;p&gt;```ts
User.findAll({
  attributes: [
    [&amp;#39;count(id)&amp;#39;, &amp;#39;count&amp;#39;]
  ]
});
```&lt;/p&gt;
&lt;p&gt;Produced&lt;/p&gt;
&lt;p&gt;```sql
SELECT count(id) AS &amp;#34;count&amp;#34; FROM &amp;#34;users&amp;#34;
```&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;This feature was deprecated in Sequelize 5, and using it prints a deprecation warning.&lt;/p&gt;
&lt;p&gt;This issue has been patched in [`@sequelize/core@7.0.0.alpha-20`](https://github.com/sequelize/sequelize/pull/15374) and [`sequelize@6.29.0`](https://github.com/sequelize/sequelize/pull/15710).&lt;/p&gt;
&lt;p&gt;In Sequelize 7, it now produces the following:&lt;/p&gt;
&lt;p&gt;```sql
SELECT &amp;#34;count(id)&amp;#34; AS &amp;#34;count&amp;#34; FROM &amp;#34;users&amp;#34;
```&lt;/p&gt;
&lt;p&gt;In Sequelize 6, it throws an error explaining that we had to introduce a breaking change, and requires the user to explicitly opt-in to either the Sequelize 7 behavior (always escape) or the Sequelize 5 behavior (inline attributes that include `()` without escaping). See https://github.com/sequelize/sequelize/pull/15710 for more information.&lt;/p&gt;
&lt;p&gt;### Mitigations&lt;/p&gt;
&lt;p&gt;Do not use user-provided content to build your list or attributes. If you do, make sure that attribute in question actually exists on your model by checking that it exists in the `rawAttributes` property of your model first.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;A discussion thread about this issue is open at https://github.com/sequelize/sequelize/discussions/15694
CVE: CVE-2023-22578&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f598-mfpv-gmfx</guid>
    </item>
    <item>
      <title>gsd-2023-22578</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-22578</link>
      <description>gsd-2023-22578</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-22578</guid>
    </item>
  </channel>
</rss>
