VYPR
High severity8.1NVD Advisory· Published Mar 26, 2026· Updated Jun 17, 2026

CVE-2026-33442

CVE-2026-33442

Description

Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the sanitizeStringLiteral method in Kysely's query compiler escapes single quotes (' → '') but does not escape backslashes. On MySQL with the default BACKSLASH_ESCAPES SQL mode, an attacker can inject a backslash before a single quote to neutralize the escaping, breaking out of the JSON path string literal and injecting arbitrary SQL. Version 0.28.14 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
kyselynpm
>= 0.28.12, < 0.28.140.28.14

Affected products

2
  • cpe:2.3:a:kysely:kysely:*:*:*:*:*:node.js:*:*
    Range: >=0.28.12,<0.28.14
  • ghsa-coords
    Range: >= 0.28.12, < 0.28.14

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.