VYPR
Critical severity9.8NVD Advisory· Published Jul 4, 2022· Updated Jun 17, 2026

CVE-2022-33171

CVE-2022-33171

Description

The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, supplying a crafted FindOneOptions instead of an id string leads to SQL injection. NOTE: the vendor's position is that the user's application is responsible for input validation

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
typeormnpm
< 0.3.00.3.0

Affected products

3
  • Typeorm/Typeorm2 versions
    cpe:2.3:a:typeorm:typeorm:*:*:*:*:*:node.js:*:*+ 1 more
    • cpe:2.3:a:typeorm:typeorm:*:*:*:*:*:node.js:*:*range: <0.3.0
    • (no CPE)
  • ghsa-coords
    Range: < 0.3.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.