sequelize-typescript@1.1.0 vulnerabilities

Decorators and some other features for sequelize

Direct Vulnerabilities

Known vulnerabilities in the sequelize-typescript package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

sequelize-typescript is a Decorators and some other features for sequelize

Affected versions of this package are vulnerable to Prototype Pollution in the deepAssign() function in shared/object.ts. An attacker can render objects unusable by overriding their attributes with unexpected values.

How to fix Prototype Pollution?

Upgrade sequelize-typescript to version 2.1.6 or higher.

<2.1.6