GHSA-gpj5-g38j-94v9
HIGHCVE-2026-39356Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions, embedded identifier delimiters were not escaped before the identifier was wrapped in quotes or backticks.
- Affected
- < 0.45.2, >=0, <0.45.2, >=1.0.0-beta.2, <1.0.0-beta.20
- Fixed in
- 0.45.2
- Weakness
- CWE-89
- Published
- 2026-04-08
- Source
- github