CVE-2025-60542
Severity CVSS v4.0:
Pending analysis
Type:
CWE-89
SQL Injection
Publication date:
29/10/2025
Last modified:
30/10/2025
Description
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



