Feather-Sequelize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
{ "github_reviewed_at": "2022-10-31T19:25:00Z", "cwe_ids": [ "CWE-1321" ], "nvd_published_at": "2022-10-26T10:15:00Z", "severity": "CRITICAL", "github_reviewed": true }