0.28.0
7 years ago
6 months ago
Known vulnerabilities in the @nozbe/watermelondb package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@nozbe/watermelondb is a Reactive & asynchronous database for powerful React and React Native apps. Affected versions of this package are vulnerable to SQL Injection. A maliciously crafted record ID can exploit a SQL Injection vulnerability in iOS adapter implementation and cause the app to delete all or selected records from the database, generally causing the app to become unusable. How to fix SQL Injection? Upgrade | <0.15.1 |