GHSA-wmw4-mw6x-6vfm: ReactPress has SQL injection via dynamic column names in TypeORM query builders
HIGHHigh-risk vulnerability — CVSS 7.5
## Summary ReactPress API list endpoints build TypeORM `QueryBuilder` conditions using unsanitized HTTP query parameter *names* as SQL column identifiers (e.g. `` `article.${key}` ``). TypeORM parameterizes values but not column names, allowing unauthenticated attackers to inject SQL through crafted query string keys. ## Impact An unauthenticated remote attacker can perform blind SQL injection against the application database, potentially exfiltrating sensitive data (users, settings, API keys, article content, etc.). …
CVE · detail
- CVE-2026-61685nvd ↗EPSS 0.53%
Early access
Get the next one first.
Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.
bot-protected