CVE-2026-19351
node-sql-query SelectQuery SQL injection (Select.js from/build parameter manipulation)
- Severity
- high
- Affected product
- sql-query
- Affected versions
- sql-query ≥ 0.1.25, ≤ 0.1.28
- Fixed in
- sql-query 0.1.29
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints sql-query from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23, closing D97. THE KEY IS THE REGISTRY NAME, verified against the npm registry the same day: the package is 'sql-query' on npm (dresende/node-sql-query on GitHub), and NEITHER 'sql' (brianc's unrelated node-sql) NOR 'node-sql-query' (Naujiano's MSSQL interface, versions 0.1.0-0.2.0) is it - keying by the registry name means neither wrong package can join this row through a served manifest. Affected versions are the advisory's exact list 0.1.25/0.1.26/0.1.27/0.1.28; 0.1.29 (published 2026-07-26) is the current release and the fix. Reachable only via an exposed package.json/package-lock.json pin (version_tools._MANIFESTS), the Log4j shape: a library with no HTTP surface of its own.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →