CVE-2026-34220Disclosure(mikro-orm / mikroorm)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mikro-orm mikroorm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mikroorm

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-31); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
mikroorm

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-30: 1Mentions · 2026-03-31: 2Mentions · 2026-04-01: 1Mentions · 2026-04-02: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-01: 1Patch / Workaround · 2026-04-02: 1Technical Details · 2026-03-30: 1Technical Details · 2026-03-31: 2Technical Details · 2026-04-01: 1Technical Details · 2026-04-02: 103-3003-3104-0104-02
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-301
Patch1
2026-03-312
Disclosure2
2026-04-011
Patch1
2026-04-021
Disclosure1
Full discourse5 posts
  • Misbar | مسبار@MisbarSec
    Disclosure

    📌 ثغرة حقن SQL حرجة بتقييم 9.3 CVSS تستهدف MikroORM وتعرض 2 مليون مستخدم شهرياً للخطر اكتُشفت ثغرة أمنية حرجة من نوع SQLi (CVE-2026-34220) في MikroORM، وهو مُخطط كائنات علائقي (ORM) يعتمد على TypeScript ومستخدم على نطاق واسع في Node.js. تحمل الثغرة تقييم خطورة 9.3 CVSS، مما يشير إلى قدرتها على إحداث تأثير كبير. تهدد هذه الثغرة أكثر من مليوني مستخدم شهرياً، حيث يمكن استغلالها لتنفيذ تعليمات SQL خبيثة والتأثير على سلامة البيانات وسريتها. يُنصح المطورون بتحديث حزم MikroORM فوراً وتطبيق ممارسات الترميز الآمن للتخفيف من المخاطر. 🔗 للمزيد: https://securityonline.info/mikroorm-sql-injection-vulnerability-cve-2026-34220-9-3-cvss/

    Post summary

    A critical SQL injection flaw (CVE‑2026‑34220) in MikroORM, with a CVSS 9.3 and affecting over 2 million users, requires immediate package updates to mitigate the risk.

    00030288
    245 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    2M+ monthly users are at risk as MikroORM patches a critical 9.3 CVSS SQL injection flaw (CVE-2026-34220). Update to 6.6.10 or 7.0.6 immediately to stay safe #MikroORM #SQLInjection #CyberSecurity #InfoSec #NodeJS #TypeScript #Vulnerability #PatchNow #CVE https://securityonline.info/mikroorm-sql-injection-vulnerability-cve-2026-34220-9-3-cvss/ https://t.co/9H0OtIAX8j

    Post summary

    The tweet announces a critical SQL injection vulnerability in MikroORM and urges users to apply the available patch by updating to specified versions.

    00011255
    11.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-34220: MikroORM is vulnerable to SQL In... Object-to-SQL parsing bypass in MikroORM lets attackers inject raw SQL through crafted payloads—classic ORM trust bound... https://zerodaysignal.com/vulnerability/CVE-2026-34220 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a new SQL injection vulnerability (CVE‑2026‑34220) in MikroORM via an object‑to‑SQL parsing bypass, citing a link for more details but providing no evidence of active exploitation, a patch, or PoC.

    0000052
    194 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical SQL Injection vulnerability (CVE-2026-34220) affects `MikroORM` via specially crafted objects. Review input validation and sanitization practices for database interactions. #SQLi #MikroORM #infosec https://www.pulsepatch.io/posts/cve-2026-34220-mikroorm-sql-injection

    Post summary

    A new critical SQL Injection vulnerability (CVE‑2026‑34220) affecting MikroORM has been disclosed; no exploit, PoC, or fix details are provided at this time.

    0000022
    6 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 MikroORM SQL injection flaw CVE-2026-34220 puts affected apps at risk. Patch now. Until then, use strong input validation. 🔗 https://vulert.com/vuln-db/CVE-2026-34220 #CyberSecurity #MikroORM #SQLInjection #AppSec #DevSecOps https://t.co/ec1FEMBfKW

    Post summary

    The tweet highlights a MikroORM SQL injection vulnerability (CVE‑2026‑34220), urging users to apply the patch immediately and mitigate via input validation until the fix is available.

    0000037
    122 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmikro-ormmikroorm-node.js-

Explore more