TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Supports MongoDB, MySQL, PostgreSQL and SQLite databases as well as usage with vanilla JavaScript.
100%
Total Score
100
100
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-449141 New @mikro-orm/core is vulnerable to Prototype Pollution in versions 6.0.0 - 6.6.15 and 7.0.0 - 7.1.6. | 6.0.0 - 6.6.157.0.0 - 7.1.6 | Medium |
CVE-2026-34221 @mikro-orm/core is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 6.6.10 and 7.0.0-dev.0 - 7.0.6. | 0.0.0 - 6.6.107.0.0-dev.0 - 7.0.6 | High |
CVE-2026-34220 @mikro-orm/core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.6.10 and 7.0.0-dev.0 - 7.0.6. | 0.0.0 - 6.6.107.0.0-dev.0 - 7.0.6 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant