Versions of mysql prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in the mysql.escape() function, which does not properly escape object keys.
Update to version 2.0.0-alpha8 or later.
{
"github_reviewed_at": "2020-08-31T18:09:53Z",
"nvd_published_at": "2018-05-29T20:29:00Z",
"cwe_ids": [
"CWE-89"
],
"severity": "MODERATE",
"github_reviewed": true
}