Executive brief
TypeORM is a popular object-relational mapping (ORM) library used by developers to interact with databases in Node.js applications. A SQL injection vulnerability allows attackers to inject malicious SQL commands by crafting specially-formed object payloads in repository.save() or repository.update() operations, potentially leading to unauthorized data modification or exposure. This affects applications using TypeORM versions before 0.3.26 with MySQL or MySQL2 database drivers.
Technical details
This is a SQL injection vulnerability (CWE-89) in TypeORM's MySQL driver caused by incorrect configuration of the mysql2 client library. The root cause is that TypeORM does not explicitly set the stringifyObjects option when initializing mysql2, causing it to default to false. This default behavior causes the underlying sqlstring library to parse plain JavaScript objects into malformed SQL syntax, allowing attackers to inject additional column assignments. An attacker can exploit this by sending a request with a nested object in request.body (e.g., city[name] and city[role]) which are then passed directly to repository.save() or repository.update(). The vulnerability requires network access to the application and no authentication, but does require the application to pass user-controlled data directly into the ORM methods without filtering. The fix sets stringifyObjects: true explicitly, which is available in TypeORM 0.3.26 and later.
Affected products
- TypeORM TypeORM before 0.3.26
Timeline
- 2025-10-29: disclosed
- 2025-10-29: patched: Fixed in version 0.3.26
- 2025-10-31: advisory: GHSA-q2pj-6v73-8rgj published