{"api_version":"1","generated_at":"2026-07-23T10:22:35+00:00","cve":"CVE-2019-10752","urls":{"html":"https://cve.report/CVE-2019-10752","api":"https://cve.report/api/cve/CVE-2019-10752.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10752","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10752"},"summary":{"title":"CVE-2019-10752","description":"Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2019-10-17 19:15:00","updated_at":"2023-11-07 03:02:00"},"problem_types":["CWE-89"],"metrics":[],"references":[{"url":"https://github.com/sequelize/sequelize/commit/9bd0bc1%2C","name":"https://github.com/sequelize/sequelize/commit/9bd0bc1%2C","refsource":"","tags":[],"title":"","mime":"inode/x-empty","httpstatus":"403","archivestatus":"404"},{"url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751","name":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"SQL Injection in sequelize | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/sequelize/sequelize/commit/9bd0bc1,","name":"https://github.com/sequelize/sequelize/commit/9bd0bc1,","refsource":"MISC","tags":["Broken Link"],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751,","name":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751,","refsource":"CONFIRM","tags":["Not Applicable"],"title":"Invalid vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"0"},{"url":"https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e","name":"https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"fix(sequelize.json.fn): use common path extraction for mysql/mariadb/… · sequelize/sequelize@9bd0bc1 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751%2C","name":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751%2C","refsource":"","tags":[],"title":"Page not found | Snyk","mime":"text/html","httpstatus":"422","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10752","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10752","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10752","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sequelizejs","cpe5":"sequelize","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10752","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sequelizejs","cpe5":"sequelize","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"node.js","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10752","qid":"981638","title":"Nodejs (npm) Security Update for sequelize (GHSA-m9jw-237r-gvfv)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10752","ASSIGNER":"report@snyk.io","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"sequelize","version":{"version_data":[{"version_value":"All versions prior to version 4.44.3 and 5.15.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"SQL Injection"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://github.com/sequelize/sequelize/commit/9bd0bc1,","url":"https://github.com/sequelize/sequelize/commit/9bd0bc1,"},{"refsource":"MISC","name":"https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e","url":"https://github.com/sequelize/sequelize/commit/9bd0bc111b6f502223edf7e902680f7cc2ed541e"},{"refsource":"CONFIRM","name":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751,","url":"https://snyk.io/vuln/SNYK-JS-SEQUELIZE-459751,"}]},"description":{"description_data":[{"lang":"eng","value":"Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite."}]}},"nvd":{"publishedDate":"2019-10-17 19:15:00","lastModifiedDate":"2023-11-07 03:02:00","problem_types":["CWE-89"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sequelizejs:sequelize:*:*:*:*:*:node.js:*:*","versionStartIncluding":"5.0.0","versionEndExcluding":"5.15.1","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sequelizejs:sequelize:*:*:*:*:*:node.js:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.44.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10752","Ordinal":"149031","Title":"CVE-2019-10752","CVE":"CVE-2019-10752","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10752","Ordinal":"1","NoteData":"Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10752","Ordinal":"2","NoteData":"2019-10-17","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10752","Ordinal":"3","NoteData":"2019-10-17","Type":"Other","Title":"Modified"}]}}}