@nozbe/watermelondb@0.12.1-3 vulnerabilities

Build powerful React Native and React web apps that scale from hundreds to tens of thousands of records and remain fast

Direct Vulnerabilities

Known vulnerabilities in the @nozbe/watermelondb package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
SQL Injection

@nozbe/watermelondb is a Reactive & asynchronous database for powerful React and React Native apps.

Affected versions of this package are vulnerable to SQL Injection. A maliciously crafted record ID can exploit a SQL Injection vulnerability in iOS adapter implementation and cause the app to delete all or selected records from the database, generally causing the app to become unusable.

How to fix SQL Injection?

Upgrade @nozbe/watermelondb to version 0.15.1 or higher.

<0.15.1