CVE-2026-19351Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. Upgrading to version 0.1.29 addresses this issue. The patch is named 3414c42f6de89826fa1f5f36f6139d1e6552778e. Upgrading the affected component is recommended.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-09: 3PoC Mentioned / Linked · 2026-08-09: 1Technical Details · 2026-08-09: 108-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-19351 A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in… https://www.cve.org/CVERecord?id=CVE-2026-19351

    Post summary

    The text announces CVE‑2026‑19351, lists affected package versions and functions, but provides no further technical details, patches, or exploitation information.

    010001.9K
    57.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19351 A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in… https://www.cve.org/CVERecord?id=CVE-2026-19351 ----- Traducción: CVE-2026-19351 Se … http://infoflow.cloud`

    Post summary

    The post announces the disclosure of CVE-2026-19351 impacting dresende node-sql-query versions 0.1.25‑0.1.28, with the vulnerable functions identified and a link to the official CVE record.

    0000028
    98 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-19351](https://github.com/dresende/node-sql-query/) A vulnerability was found in dresen... https://github.com/dresende/node-sql-query/ #Vulnerability #CVE #ZeroDay

    Post summary

    The tweet announces the CVE-2026-19351 vulnerability in dresende/node-sql-query, links to a GitHub repository likely containing PoC code, but it does not provide technical details or evidence of active exploitation.

    0000046
    18 followersView on X

Explore more