Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q2pj-6v73-8rgj | TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update |
Wed, 12 Nov 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | TypeORM: SQL Injection via crafted request to repository.save or repository.update | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 30 Oct 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-89 | |
| Metrics |
cvssV3_1
|
Thu, 30 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Typeorm
Typeorm typeorm |
|
| Vendors & Products |
Typeorm
Typeorm typeorm |
Wed, 29 Oct 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-30T20:28:41.544Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60542
Updated: 2025-10-30T20:28:36.071Z
Status : Deferred
Published: 2025-10-29T16:15:34.057
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-60542
OpenCVE Enrichment
Updated: 2025-10-30T14:38:36Z
Github GHSA