HIGHnpm →
TypeORM: migration:generate template-literal code injection
TypeORM: migration:generate template-literal code injection
Affected packages
- typeorm
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/typeorm/typeorm/security/advisories/GHSA-2rp8-mm9q-fp49
- https://github.com/typeorm/typeorm/commit/41d1c62fe49f99c3ca916d4d986f61ee9f45d519
- https://github.com/typeorm/typeorm/commit/b175f9b8be422edd2a2ac035ba90c3f2ce782dfe
- https://github.com/typeorm/typeorm
- https://github.com/typeorm/typeorm/releases/tag/0.3.31
- https://github.com/typeorm/typeorm/releases/tag/1.1.0
Structured record: https://osv.dev/vulnerability/GHSA-2rp8-mm9q-fp49
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta