CVE-2026-30951 | Sequelize up to 6.37.7 _traverseJSON sql injection (GHSA-6457-6jrx-69cr / Nessus ID 301792)
A vulnerability has been found in Sequelize up to 6.37.7 and classified as critical. Affected by this vulnerability is the function _traverseJSON. This manipulation causes sql injection.
This vulnerability is registered as CVE-2026-30951. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.