CVE-2025-32020

CRITICAL

crud-query-parser < 0.1.0 - SQL Injection via TypeORM Order/Sort Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-32020. PoCs published by AikidoSec.

AI-analyzed exploit summary This repository contains functional exploit code demonstrating JavaScript injection vulnerabilities in Node.js applications, specifically targeting the `@enspirit/elo` library. The PoC includes both vulnerable and protected test cases, showcasing how the Aikido Zen Firewall blocks the attack.

Description

The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/sort parameter in the TypeORM adapter, which allows SQL injection. You are impacted by this vulnerability if you are using the TypeORM adapter, ordering is enabled and you have not set-up a property filter. This vulnerability is fixed in 0.1.0.

Exploits (1)

github WORKING POC 6 stars
by AikidoSec · javascriptpoc
https://github.com/AikidoSec/zen-0-days/tree/main/node/CVE-2025-32020

This repository contains functional exploit code demonstrating JavaScript injection vulnerabilities in Node.js applications, specifically targeting the `@enspirit/elo` library. The PoC includes both vulnerable and protected test cases, showcasing how the Aikido Zen Firewall blocks the attack.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Node.js applications using @enspirit/elo library
No auth needed
Prerequisites: Node.js environment · Docker for containerized testing
devstral-2 · analyzed Feb 27, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v4 9.3
EPSS 0.0022
EPSS Percentile 45.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (2)
Guichaguri/crud-query-parser < 0.1.0
npm/crud-query-parser 0 - 0.1.0npm
Published Apr 08, 2025
Tracked Since Feb 18, 2026