Description

SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.

INFO

Published Date :

2025-10-29T00:00:00.000Z

Last Modified :

2025-10-30T20:28:41.544Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-60542 vulnerability.

Vendors Products
Typeorm
  • Typeorm

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact