What is CVE-2026-73651?
A high-severity vulnerability in TypeORM affects versions prior to 0.3.31 and 1.1.0. The 'typeorm migration:generate' command embeds database schema metadata into template literals, potentially exposing sensitive information. Users should upgrade to versions 0.3.31 or 1.1.0 to mitigate the risk.
Azərbaycanca: TypeORM ORM kitabxanasında yüksək kritik zəiflik aşkarlanıb. `typeorm migration:generate` əmri verilənlər bazası sxemi metadata-sını şablon sətirlərə yerləşdirdiyi üçün məxfi məlumatların ifşa riski yaranır. Təsirə məruz qalmamaq üçün 0.3.31 və ya 1.1.0 versiyalarına yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which operation in TypeORM triggers the sensitive information exposure risk associated with CVE-2026-73651?
The risk is triggered when the `typeorm migration:generate` command embeds database schema metadata into template literals, potentially exposing sensitive information.
To mitigate CVE-2026-73651, which TypeORM versions should users upgrade to?
Users should upgrade to versions 0.3.31 or 1.1.0 to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.