PT-2025-44304 · Typeorm · Typeorm

CVE-2025-60542

·

Published

2025-10-29

·

Updated

2026-08-24

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TypeORM versions prior to 0.3.26
Description A SQL Injection issue exists in TypeORM. This is due to the sqlstring call using stringifyObjects set to false when processing requests to repository.save or repository.update. A crafted request can exploit this to inject malicious SQL code.
Recommendations Update TypeORM to version 0.3.26 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60542
GHSA-Q2PJ-6V73-8RGJ

Affected Products

Typeorm