@mikro-orm/core 7.2.0 appears to be a healthy dependency: it has a long release history with 1,219 releases in the last 12 months, is not deprecated, has current repository activity, broad recent contributor participation, strong organization backing, build provenance, tests and a changelog in the repository, and no install-time lifecycle scripts. The main residual concern is that most recent releases are prereleases and one release workflow has top-level write permissions, while commit activity is concentrated in one contributor; however, the stable-major status, active secondary contributors, organization-owned project, and substantial repository hygiene materially reduce those concerns.
91%
Total Score
100
100
95
90
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-392862 @mikro-orm/core is vulnerable to Prototype Pollution in versions 4.0.4 - 7.1.11. | 4.0.4 - 7.1.11 | Medium |
AIKIDO-2026-189719 @mikro-orm/core is vulnerable to Prototype Pollution in versions 5.0.1 - 7.1.10. | 5.0.1 - 7.1.10 | Low |
AIKIDO-2026-449141 @mikro-orm/core is vulnerable to Prototype Pollution in versions 6.0.0 - 6.6.15 and 7.0.0 - 7.1.6. | 6.0.0 - 6.6.157.0.0 - 7.1.6 | Medium |
CVE-2026-34221 @mikro-orm/core is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in versions 0.0.0 - 6.6.10 and 7.0.0-dev.0 - 7.0.6. | 0.0.0 - 6.6.107.0.0-dev.0 - 7.0.6 | High |
CVE-2026-34220 @mikro-orm/core is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.6.10 and 7.0.0-dev.0 - 7.0.6. | 0.0.0 - 6.6.107.0.0-dev.0 - 7.0.6 | Critical |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.