MEDIUM
typeorm
CVE published 2026-08-13
CVE-2026-73651
CVE-2026-73651 is a code injection vulnerability in TypeORM, a TypeScript and JavaScript ORM for Node.js. An attacker with database schema write access can inject malicious code via column COMMENT or DEFAULT metadata, which is executed when the generated migration is loaded. Defenders should verify exposure in Node.js environments using TypeORM versions before 0.3.31 and 1.1.0, assess database schema meta [truncated]