A critical SQL injection flaw tracked as CVE-2026-69240 affects Sequelize when used with the Oracle database dialect, exposing applications that run versions prior to 6.37.4. The vulnerability lies in the ORM's sql-string.js escape logic, which fails to properly escape quotes when a supplied string begins with Oracle function names such as TO_DATE or TO_TIMESTAMP, causing attacker-controlled input to be inserted directly into generated SQL queries.
The issue is rated CVSS 9.8 and can be exploited remotely without authentication, potentially allowing attackers to bypass application controls, read sensitive data, alter or delete records, and execute arbitrary SQL expressions. Reports warn that in Oracle deployments with elevated database privileges, the impact could extend beyond the database to filesystem access or operating system command execution, creating a path to full host compromise. The vendor has released a fix in Sequelize 6.37.4 and advises affected users to upgrade immediately.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
The SQL injection vulnerability affecting Sequelize was assigned/disclosed as CVE-2026-69240, with the CVE record stating it was newly received by security-advisories@github.com. The disclosure references a GitHub Security Advisory for the issue.
Sequelize addressed an SQL injection flaw affecting its Oracle dialect handling in release 6.37.4. The fix corrected escaping behavior in sql-string.js for strings beginning with TO_TIMESTAMP or TO_DATE.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.