CRITICAL
sequelize
CVE published 2026-08-03
CVE-2026-69240
This debrief summarizes the CVE-2026-69240 vulnerability in the Sequelize Node.js ORM tool. The vulnerability allows for SQL injection attacks when the dialect is set to Oracle and user input starts with specific date functions. Affected product deployments should be confirmed in managed environments, with an owner assigned for follow-up. The official advisory or CVE record should be reviewed to validate [truncated]