This page lists publicly disclosed CVE vulnerabilities affecting feathersjs feathers-sequelize (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2022-2422 | Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is used. | [email protected] | 10.0 | 0.73% | 2022-10-26 | 2026-06-17 |
| CVE-2022-29823 | Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application. | [email protected] | 10.0 | 1.39% | 2022-10-26 | 2026-06-17 |
| CVE-2022-29822 | Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection | [email protected] | 10.0 | 0.73% | 2022-10-26 | 2026-06-17 |