fix(deps): update dependency typeorm to ^0.3.0 [security] - #36
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency typeorm to ^0.3.0 [security]#36renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
August 12, 2025 00:10
c9f8cf1 to
527758c
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
August 23, 2025 16:00
527758c to
de7e964
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
September 1, 2025 02:28
de7e964 to
19b8a54
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
September 26, 2025 23:55
19b8a54 to
2984cf0
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
October 23, 2025 06:32
2984cf0 to
c64a93a
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
November 1, 2025 12:14
c64a93a to
f52a6e9
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
November 16, 2025 07:44
f52a6e9 to
bd5880f
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
2 times, most recently
from
November 20, 2025 15:14
f397066 to
f163be2
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
December 4, 2025 19:24
f163be2 to
6ddd56a
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
December 5, 2025 15:49
6ddd56a to
9c0894c
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
December 30, 2025 11:49
9c0894c to
6790134
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
January 2, 2026 07:43
6790134 to
e319cab
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
January 9, 2026 15:04
e319cab to
7366b4c
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
January 10, 2026 07:39
7366b4c to
1b00823
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
January 20, 2026 11:40
1b00823 to
aed0268
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
January 21, 2026 19:24
aed0268 to
cf5d5a6
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
February 3, 2026 07:45
cf5d5a6 to
e19154c
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
March 15, 2026 00:19
07678ba to
4e7ac19
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
April 15, 2026 18:18
4e7ac19 to
3c1b5e4
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
2 times, most recently
from
May 3, 2026 07:30
f0bccc1 to
ae9eb33
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 13, 2026 06:59
ae9eb33 to
8af9079
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 14, 2026 11:38
8af9079 to
1959ce1
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 16, 2026 06:51
1959ce1 to
e0b8c06
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 17, 2026 07:53
e0b8c06 to
80e1f0a
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 21, 2026 08:06
80e1f0a to
5f38d1e
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 24, 2026 08:05
5f38d1e to
4d78b38
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
May 30, 2026 19:05
4d78b38 to
b5aa349
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
2 times, most recently
from
June 6, 2026 23:39
c73cc10 to
9223086
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
June 12, 2026 16:10
9223086 to
d8e6128
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
June 14, 2026 08:13
d8e6128 to
069b9e5
Compare
renovate
Bot
force-pushed
the
renovate/npm-typeorm-vulnerability
branch
from
July 16, 2026 07:40
069b9e5 to
0842d80
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
^0.2.18→^0.3.0SQL injection in typeORM
CVE-2022-33171 / GHSA-fx4w-v43j-vc45
More information
Details
The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
CVE-2025-60542 / GHSA-q2pj-6v73-8rgj
More information
Details
Summary
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
Details
Vulnerable Code:
Intended Payload (non-malicious):
username=myusername&city=Riga&name=JavadOR
{username:\"myusername\",phone:12345,name:\"Javad\"}SQL query produced:
Malicious Payload:
username=myusername&city[name]=Riga&city[role]=adminOR
{username:\"myusername\",city:{name:\"Javad\",role:\"admin\"}}SQL query produced with Injected Column:
Above query is valid as
city=name=Javadis a boolean expression resulting incity= 1 (false). “role” column is injected and updated.Underlying issue was due to TypeORM using mysql2 without specifying a value for the stringifyObjects option. In both mysql and mysql2 this option defaults to false. This option is then passed into SQLString library as false. This results in sqlstring parsing objects in a strange way using objectToValues.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:L/E:PReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
TypeORM: SQL Injection in UpdateQueryBuilder/SoftDeleteQueryBuilder orderBy (MySQL/MariaDB)
GHSA-9ggv-8w38-r7pm
More information
Details
Impact
Blind SQL injection vulnerability in
UpdateQueryBuilderandSoftDeleteQueryBuilderaffecting MySQL and MariaDB users.UpdateQueryBuilderandSoftDeleteQueryBuilder(including theiraddOrderByvariants) do not validate theorderparameter against an allowlist of permitted values (ASC/DESC). The caller-supplied value is stored verbatim and concatenated directly into the generated SQL string without quoting or parameterization.SelectQueryBuilder.orderByperforms this validation correctly; the affected builders do not.If any code path passes user-controlled input to
orderBy/addOrderByon an update or soft-delete query, an attacker can inject arbitrary SQL via the sort direction — even when the column name itself is hardcoded.Demonstrated impact includes:
SLEEP()to infer secret values bit by bit)LIMITpatternsSLEEP()-based query exhaustionCVSS 3.1: 8.6 (High) —
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:LAffected files (relative to commit
73fda419):src/query-builder/UpdateQueryBuilder.ts: lines 383–419 and 718–744src/query-builder/SoftDeleteQueryBuilder.ts: lines 352–388 and 520–546The vulnerability was introduced in commit
03799bd2(v0.1.12) and is present through the latest release (v0.3.28).Patches
A fix has been released in 0.3.29 (1b66c44) and 1.0.0 (93eec63).
Workarounds
Applications can manually validate the
orderargument before passing it toorderByoraddOrderByon update or soft-delete query builders:Do not pass user-controlled values to
orderBy/addOrderByonUpdateQueryBuilderorSoftDeleteQueryBuilderwithout this validation.References
SelectQueryBuilder.orderByfor the correct validation pattern this fix should mirrorSeverity
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
TypeORM: migration:generate template-literal code injection
CVE-2026-73651 / GHSA-2rp8-mm9q-fp49
More information
Details
Summary
typeorm migration:generateembeds database schema metadata into JS/TS template literals, escaping backticks but not${...}. An attacker who can write schema metadata (column comments, defaults, view definitions) achieves arbitrary code execution on the host that loads the generated migration.Details
MigrationGenerateCommand.ts(L117-138) wraps each SQL statement in a JS template literal, escaping only backticks:Introspected schema strings reach this sink through driver query runners:
DEFAULT,COMMENT,CHECKconstraints, view definitionsPostgresQueryRunner.ts:1782,L1898,L2287,L4125COLUMN_DEFAULT,COLUMN_COMMENTMysqlQueryRunner.ts:2873-2974,L3580-3583CockroachQueryRunner.tsescapeComment()on each driver strips only null bytes, leaving${...}intact:When the migration file is loaded (
migration:run,import, orrequire), the JS engine evaluates${...}as live interpolation.Affected source:
MigrationGenerateCommand.tsPostgresDriver.tsescapeComment()— PostgresMysqlDriver.tsescapeComment()— MySQLCockroachDriver.tsescapeComment()— CockroachDBConfirmed injection vectors (MySQL):
COMMENTDEFAULTALTER TABLE ... DEFAULT '${...}'; payload appears in generated migrationCHECKconstraintinformation_schema.CHECK_CONSTRAINTSstrips content fromCHECK_CLAUSEViewEntityintrospection; likely exploitable viapg_get_viewdef()Suggested fix: Escape
${to\${(and\\to\\\\) before embedding query strings into template literals, or switch to emitting the SQL as aJSON.stringify()-encoded regular string argument.PoC
Prerequisites:
migration:generateCOMMENT,DEFAULT, or view definition textSteps:
${...}:.tsfile contains unescaped${...}:Output confirms code execution —
idran on the host and its output was interpolated into the SQL:The payload appears in whichever migration direction restores the DB's current state. A malicious DB comment with a clean entity comment places it in
down(). Attacker-influenced entity metadata places it inup(). Either direction executes the code when the method runs.Impact
Code injection / RCE. An attacker with DB schema write access executes arbitrary JavaScript on any machine that generates and loads the migration. This crosses the DB-to-host trust boundary.
CI/CD pipelines that auto-generate and run migrations are the highest-risk target. Any TypeORM user running
migration:generateagainst a database with attacker-influenced schema metadata is affected.Severity
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
typeorm/typeorm (typeorm)
v0.3.31Compare Source
Bug Fixes
require()calls that break bundlers (#12647) (30f9fc7)Full Changelog: typeorm/typeorm@0.3.30...0.3.31
v0.3.30Compare Source
The list below is the set of commits between
0.3.30and1.0.0— fixes already shipped on the0.3.xline are listed under their respective0.3.xentries below.Bug Fixes
shortenmethod to properly work with camelCase_aliases (#11283) (8a9a376)timestamptzpersistence/hydration correctly (#11774) (c26fc33)queryBuilder.update(#11296) (7084240)Features
incrementanddecrementofEntityManager(#11294) (2260718)joinproperty (#12375) (f4f762e)ADD VALUEwhen changing enum values if possible (#10956) (f1be21e)INSERT INTO ... SELECT FROM ...in QueryBuilder (#11896) (8fc0915)Performance Improvements
BREAKING CHANGES
0.3.30 (2026-05-18)
Bug Fixes
Reverts
0.3.29 (2026-05-08)
Bug Fixes
QueryBuilderparameter of type JSDatenot escaped correctly (#11867) (5153436)Features
returningoption to update/upsert operations (#11782) (11d9767)0.3.28 (2025-12-02)
Bug Fixes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.