HIGH
drizzle-team
CVE published 2026-04-07
CVE-2026-39356
Drizzle ORM, a modern TypeScript ORM, has a vulnerability in versions prior to 0.45.2 and 1.0.0-beta.20. The vulnerability involves improper escaping of quoted SQL identifiers, which allows attackers to inject SQL by terminating the quoted identifier. This issue affects applications that pass attacker-controlled input to APIs constructing SQL identifiers or aliases. The vulnerability is fixed in versions [truncated]