Sequelize is a promise-based Node.js ORM tool for Postgres, MySQL, MariaDB, SQLite, Microsoft SQL Server, Amazon Redshift and Snowflake’s Data Cloud. It features solid transaction support, relations, eager and lazy loading, read replication and more.
83%
Total Score
81
61
89
100
0
| Title | Versions | Severity |
|---|---|---|
CVE-2026-69240 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.37.4. | 0.0.0 - 6.37.4 | Critical |
CVE-2026-30951 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 6.0.0-beta.1 - 6.37.7. | 6.0.0-beta.1 - 6.37.7 | High |
CVE-2023-22579 sequelize is vulnerable to Access of Resource Using Incompatible Type ('Type Confusion') in versions 0.0.0 - 6.28.1. | 0.0.0 - 6.28.1 | Critical |
CVE-2023-25813 sequelize is vulnerable to Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in versions 0.0.0 - 6.19.1. | 0.0.0 - 6.19.1 | Critical |
CVE-2023-22580 sequelize is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 6.28.1. | 0.0.0 - 6.28.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
wkx Version ^0.5.0 | — | — |
uuid Version ^8.3.2 | — | — |
debug Version ^4.3.4 | — | — |
dottie Version ^2.0.6 | — | — |
lodash Version ^4.17.21 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant