MikroORM, a TypeScript ORM for Node.js, disclosed and patched two high-severity vulnerabilities affecting releases before 6.6.10 and 7.0.6. The first, CVE-2026-34220, is a SQL injection flaw classified as CWE-89 in which specially crafted objects can be interpreted as raw SQL query fragments, creating a network-exploitable path with high confidentiality and integrity impact according to the published CVSS v4.0 assessment.
The second issue, CVE-2026-34221, is a prototype pollution vulnerability classified as CWE-1321 in MikroORM's internal Utils.merge helper. The function did not block dangerous keys such as __proto__, constructor, and prototype, allowing attacker-controlled input to alter the JavaScript object prototype. Both vulnerabilities were published through GitHub security advisories and fixed in MikroORM versions 6.6.10 and 7.0.6.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
GitHub security advisories received and published CVE-2026-34220 and CVE-2026-34221 for MikroORM on March 31, 2026. The disclosures classify the issues as CWE-89 SQL injection and CWE-1321 prototype pollution, respectively.
MikroORM fixed two vulnerabilities affecting versions prior to 6.6.10 and 7.0.6: a SQL injection issue caused by crafted objects being treated as raw SQL fragments, and a prototype pollution flaw in Utils.merge involving special keys such as __proto__, constructor, and prototype. The fixes were released in versions 6.6.10 and 7.0.6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.