CVE-2026-19351
Received Received - Intake

SQL Injection in node-sql-query Library

Vulnerability report for CVE-2026-19351, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: VulDB

Description

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
dresende node_sql_query 0.1.25
dresende node_sql_query 0.1.26
dresende node_sql_query 0.1.27
dresende node_sql_query From 0.1.29 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.
CWE-74 The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an SQL injection flaw in the node-sql-query library versions 0.1.25 to 0.1.28. It occurs in the SelectQuery.from/SelectQuery.build function in lib/Select.js where the joinType parameter is not properly validated before being used in SQL query construction. Attackers can inject malicious SQL fragments by manipulating the joinType input, potentially altering query structures or accessing unintended data.

Detection Guidance

Check if your application uses node-sql-query versions 0.1.25 to 0.1.28. Inspect code for SelectQuery.from() or SelectQuery.build() calls with joinType parameters. Look for direct user input passed to joinType without validation. Review SQL query logs for suspicious fragments like injected markers or unusual JOIN types.

Impact Analysis

If you use affected versions of node-sql-query in your application and expose the joinType parameter to user input, attackers could exploit this to inject malicious SQL. This may allow unauthorized data access, database errors, or modification of query logic. The impact depends on your application's database permissions and exposure of the vulnerable parameter.

Compliance Impact

This SQL injection vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using affected versions may face compliance violations if exploited, potentially resulting in regulatory penalties or data breach notifications.

Mitigation Strategies

Upgrade node-sql-query to version 0.1.29 or later. Implement strict allow-list validation for joinType parameters. Avoid passing untrusted input directly to joinType. Use dedicated JOIN methods if available. Review application code for exposed joinType usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19351. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart