216.73.217.24

CVE-2025-60542

· Published 29/10/2025 16:15 · Modified 29/10/2025 16:15

Labels: CVE-2025-60542 2025-10-29CVE-2025-60542[email protected]

Essential information

Published
29/10/2025 16:15
Modified
29/10/2025 16:15
Author
Creator
CISA KEV
No
CWE

Description

SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
typeorm / typeorm cpe:2.3:a:typeorm:typeorm:<0.3.26:*:*:*:*:*:*:*

References