7.5

CVE-2026-39356

SQL Injection via escapeName() in all Drizzle ORM SQL dialects

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks. As a result, applications that pass attacker-controlled input to APIs that construct SQL identifiers or aliases, such as sql.identifier(), .as(), may allow an attacker to terminate the quoted identifier and inject SQL. This vulnerability is fixed in 0.45.2 and 1.0.0-beta.20.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Drizzle ≫ Drizzle SwPlatform node.js Version < 0.45.2
Drizzle ≫ Drizzle Version 1.0.0 Update beta1 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta11 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta12 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta13 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta14 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta15 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta16 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta17 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta18 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta19 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta2 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta3 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta4 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta5 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta6 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta7 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta8 SwPlatform node.js
Drizzle ≫ Drizzle Version 1.0.0 Update beta9 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.39% 0.308
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

https://github.com/drizzle-team/drizzle-orm/security/advisories/GHSA-gpj5-g38j-94v9
Vendor Advisory