Sequelize is a promise-based Node.js ORM tool for Postgres, MySQL, MariaDB, SQLite, Microsoft SQL Server, Amazon Redshift and Snowflake’s Data Cloud. It features solid transaction support, relations, eager and lazy loading, read replication and more.
82%
Total Score
healthy
Healthy: active maintenance and a stable, licensed release outweigh workflow hygiene findings.
No build attestation or staged publishing is provided, leaving publication provenance less transparent. This is a modest supply-chain transparency gap, not evidence that the release is unsafe on its own.
A prepare script runs during installation, which adds execution-time supply-chain exposure compared with a package that has no install lifecycle behavior. No other provided signal shows that this script is unsafe.
The package has a long history and 632 releases, but only one release in the last 12 months despite a roughly two-day median interval historically. Recent repository activity and exact-version release notes partly offset the slower registry cadence.
All nine workflows were analyzed successfully, with no untrusted checkout or script-injection sink. However, high-confidence findings include blanket GitHub App permissions, an unpinned container image, and template-injection hygiene concerns, while three of 49 action references are unpinned.
| Title | Versions | Severity |
|---|---|---|
CVE-2026-69240 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.37.4. | 0.0.0 - 6.37.4 | Critical |
CVE-2026-30951 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 6.0.0-beta.1 - 6.37.7. | 6.0.0-beta.1 - 6.37.7 | High |
CVE-2023-22579 sequelize is vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in versions 0.0.0 - 6.28.1. | 0.0.0 - 6.28.1 | Critical |
CVE-2023-25813 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.19.1. | 0.0.0 - 6.19.1 | Critical |
CVE-2023-22580 sequelize is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 6.28.1. | 0.0.0 - 6.28.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
wkx Version ^0.5.0 | — | — |
uuid Version ^8.3.2 | — | — |
debug Version ^4.3.4 | — | — |
dottie Version ^2.0.6 | — | — |
lodash Version ^4.17.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.