npm package report

Is @mikro-orm/sql safe?

1 known vulnerability, worst severity HIGH.

cvss
7.6

how bad it is if exploited, out of 10

epss
1.5%

chance of exploitation in the next 30 days

xyz score
4.1

CyberXYZ composite, and a working exploit is published

fig. 01 — GHSA-cfw5-68c4-ffqp, the advisory selected below

// advisories

GHSA-cfw5-68c4-ffqp

HIGHCVE-2026-44680

MikroORM's identifier-quoting helper (Platform.quoteIdentifier and the postgres/mssql overrides) and its JSON-path emitters (Platform.getSearchJsonPropertyKey, quoteJsonKey) did not properly escape characters that delimit the SQL identifier or string-literal context they emit into. When application code passes attacker-influenced strings to public ORM APIs that expect an identifier or a JSON-prope

Affected
>=0, <6.6.14, <= 7.0.13
Fixed in
7.0.14
Weakness
CWE-89
Published
2026-05-08
Source
osv

NVDMITREOSV


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 02:32 UTC. The most recent advisory here was published 2026-05-08. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @mikro-orm/sql safe? npm package security report | CyberXYZ