
CVE-2026-30951 Sequelize is a Node.js ORM tool. Prior to 6.37.8, there is SQL injection via unescaped cast type in JSON/JSONB where clause processing. The _traverseJSON() function s… https://www.cve.org/CVERecord?id=CVE-2026-30951
Post summary
The text discloses a SQL injection vulnerability in Sequelize affecting versions prior to 6.37.8, detailing how an unescaped cast type in JSON/JSONB where clauses can be exploited, but adds no information on exploitation, patches, or PoC.
