What is CVE-2026-19351?
CVE-2026-19351 is an SQL injection vulnerability in the SelectQuery.from/SelectQuery.build function in the dresende node-sql-query library versions 0.1.25 through 0.1.28. It occurs via manipulation in the Request Parameter Handler component. Users should update to the latest patched version or sanitize inputs strictly.
Azərbaycanca: CVE-2026-19351, dresende node-sql-query kitabxanasının 0.1.25-0.1.28 versiyalarında SelectQuery.from/SelectQuery.build funksiyasında aşkarlanmış SQL injection zəifliyidir. Bu zəiflik Request Parameter Handler komponentində manipulyasiya nəticəsində baş verir. İstifadəçilər kitabxananı ən son təhlükəsiz versiyaya yeniləməli və ya daxil olan məlumatları ciddi şəkildə yoxlamalıdır.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which function of the dresende node-sql-query library was CVE-2026-19351 discovered?
The vulnerability was discovered in the library's SelectQuery.from/SelectQuery.build function.
Which versions of the dresende node-sql-query library are affected by the CVE-2026-19351 SQL injection vulnerability?
Versions 0.1.25 through 0.1.28 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.