CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-69240

criticalCVSS 9.8covered by 1 sourcefirst seen 2026-08-03
Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE. In the Oracle dialect, when val is a string and starts with TO_TIMESTAMP or TO_DATE, escape returns val directly instead of replacing single quotes. An attacker can inject arbitrary SQL expressions through an application value that reaches this escape path. This issue is fixed in version 6.37.4.

⚡ Watch CVE-2026-69240

Get an email if CVE-2026-69240 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-69240

CVE.org record

Embed the live status

CVE-2026-69240 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-69240 status](https://www.csirts.com/badge/CVE-2026-69240)](https://www.csirts.com/cve/CVE-2026-69240)