Junglewise Threat Intelligence

CVE-2026-34220: MikroORM SQL injection via crafted objects in query APIs

CVE-2026-34220 · Severity: critical · CVSS 9.8 · Published 2026-03-31

Executive brief

MikroORM is a popular tool used by Node.js developers to interact with databases. A security flaw allows attackers to bypass safety checks and execute unauthorized database commands by sending specially crafted data to an application. This could lead to the theft of sensitive customer data, unauthorized modification of records, or a complete compromise of the database.

Technical details

A SQL injection vulnerability exists in MikroORM's core due to improper neutralization of special elements in objects used for query construction. The root cause was a duck-typed detection mechanism for internal ORM marker properties; an attacker can provide a specially crafted object that mimics these internal markers, causing the ORM to interpret user-controlled input as raw SQL fragments. This affects write APIs such as wrap().assign(), nativeUpdate(), nativeInsert(), and create(). The vulnerability is reachable if untrusted user input is passed directly to these APIs without prior schema validation. The fix replaces duck-typing with symbol-based markers that cannot be spoofed via JSON/user input.

Affected products

  • mikro-orm MikroORM < 6.6.10, >= 7.0.0-rc.0, < 7.0.6

Timeline

  • 2026-03-27: advisory: GitHub Security Advisory published
  • 2026-03-31: disclosed: CVE published to NVD

References