High severity7.5NVD Advisory· Published Dec 19, 2022· Updated Jun 17, 2026
CVE-2016-20018
CVE-2016-20018
Description
Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
knexnpm | < 2.4.0 | 2.4.0 |
Affected products
2- Knex/Knex.jsdescription
Patches
Vulnerability mechanics
References
8- github.com/knex/knex/issues/1227nvdExploitIssue TrackingThird Party AdvisoryWEB
- www.ghostccamm.com/blog/knex_sqli/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-4jv9-3563-23j3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2016-20018nvdADVISORY
- github.com/knex/knex/commit/e145322da92749be7749f9ade5b5f5a66d6586a4ghsaWEB
- github.com/knex/knex/pull/5417ghsaWEB
- github.com/knex/knex/releases/tag/2.4.0ghsaWEB
- www.ghostccamm.com/blog/knex_sqlighsaWEB
News mentions
0No linked articles in our index yet.