A vulnerability in TypeORM before version 0.3.0 exists in the findOne function, which can accept either a string or a FindOneOptions object. If user-controlled input is parsed as JSON and passed to findOne, an attacker can supply a crafted FindOneOptions object instead of a simple id string, resulting in SQL injection.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Node.js/TypeScript proof-of-concept environment for CVE-2022-33171, centered around a demo Express application and a companion exploit script. The structure is simple: vulnerable-app.ts implements the HTTP server and database logic, exploit.js sends crafted requests, docker-compose.yml provisions PostgreSQL, package.json/package-lock.json define the Node dependencies, and README.md documents the vulnerability. The code is not part of a larger exploit framework. The main exploit capability is web-based interaction with a locally hosted demo service on port 4444. The exploit script first queries GET /users to confirm the target is alive and to retrieve seeded records. It then POSTs JSON to /vulnerable and /findByIds, with the latter carrying a PostgreSQL-oriented payload (1=1; SELECT pg_sleep(10) --) intended to demonstrate SQL injection or query manipulation. This indicates the exploit is aimed at showing unauthorized backend SQL execution effects, especially time-based behavior. The vulnerable application uses Express plus TypeORM with a PostgreSQL backend on localhost:5432 using hardcoded postgres/postgres credentials. It defines a User entity and initializes sample data on startup. Exposed routes are POST /vulnerable, POST /findByIds, and GET /users. Of these, /findByIds is the clearest exploitation surface because it passes attacker-controlled req.body.where into userRepo.findByIds(where). The /vulnerable route accepts email and password from JSON and performs a findOneBy lookup; despite the README claiming CVE-2022-33171 and older TypeORM behavior, the actual code uses TypeORM 0.3.7 and APIs that do not cleanly match the README’s described vulnerable pattern. That mismatch suggests the repository is more of an experimental or incomplete analysis environment than a polished reproduction. Overall, this is a real but immature PoC repository: it contains runnable exploit and target code, uses a live HTTP/database setup, and demonstrates intended SQL-injection-style behavior, but the README itself says it is a work in progress and currently not working, and the implementation does not perfectly align with the documented CVE details.
This repository demonstrates and exploits CVE-2022-33171, a SQL injection vulnerability in TypeORM versions prior to 0.3.0. The repository contains a vulnerable TypeORM application (vulnerable-app.ts) exposing endpoints /vulnerable and /findByIds, and an exploit script (exploit.js) that sends crafted HTTP requests to these endpoints. The exploit leverages the application's improper handling of user input in TypeORM's findOne and findByIds functions, allowing arbitrary SQL injection. The exploit script demonstrates both normal and malicious requests, including a time-based SQL injection payload (using pg_sleep) to show the vulnerability's impact. The repository also includes a docker-compose.yml for setting up a PostgreSQL backend. The exploit is a proof-of-concept and does not provide a weaponized or automated attack chain, but clearly demonstrates the vulnerability and its consequences.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.