← All CVEs NewScan detects
high

CVE-2026-19351

node-sql-query SelectQuery SQL injection (Select.js from/build parameter manipulation)

Severity
high
Affected product
sql-query
Affected versions
sql-query ≥ 0.1.25, ≤ 0.1.28
Fixed in
sql-query 0.1.29
Added to NewScan
2026-08-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints sql-query from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-23, closing D97. THE KEY IS THE REGISTRY NAME, verified against the npm registry the same day: the package is 'sql-query' on npm (dresende/node-sql-query on GitHub), and NEITHER 'sql' (brianc's unrelated node-sql) NOR 'node-sql-query' (Naujiano's MSSQL interface, versions 0.1.0-0.2.0) is it - keying by the registry name means neither wrong package can join this row through a served manifest. Affected versions are the advisory's exact list 0.1.25/0.1.26/0.1.27/0.1.28; 0.1.29 (published 2026-07-26) is the current release and the fix. Reachable only via an exposed package.json/package-lock.json pin (version_tools._MANIFESTS), the Log4j shape: a library with no HTTP surface of its own.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →