CVE-2025-60542

MEDIUM

TypeORM < 0.3.26 - SQL Injection via repository.save or repository.update

Title source: llm
STIX 2.1

Description

SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
npm/typeorm 0 - 0.3.26npm
Published Oct 29, 2025
Tracked Since Feb 18, 2026