CVE-2025-60542
MEDIUMCVSS 6.5/10EPSS 0.24%
Last modified
CVE-2025-60542 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-60542?
SQL Injection vulnerability in TypeORM before 0.3.26 via crafted request to repository.save or repository.update due to the sqlstring call using stringifyObjects default to false.
How severe is CVE-2025-60542?
CVE-2025-60542 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 0.24% probability of exploitation in the next 30 days.
How do I fix CVE-2025-60542?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-60536An issue in the Configure New Cluster interface of kafka-ui …7.5
- CVE-2025-60537Improper input validation in the component /kafka/ui/serdes/…6.5
- CVE-2025-60538A lack of rate limiting in the login page of shiori v1.7.4 a…6.5
- CVE-2025-6054The YANewsflash plugin for WordPress is vulnerable to Cross-…6.1
- CVE-2025-60540karakeep v0.26.0 to v0.7.0 was discovered to contain a Serve…6.5
- CVE-2025-60541A Server-Side Request Forgery (SSRF) in the /api/proxy/ comp…7.3
- CVE-2025-60547D-Link DIR600L Ax FW116WWb01 was discovered to contain a buf…7.5
- CVE-2025-60548D-Link DIR600L Ax FW116WWb01 was discovered to contain a buf…9.8
- CVE-2025-60549D-Link DIR600L Ax FW116WWb01 was discovered to contain a buf…7.5
- CVE-2025-6055The Zen Sticky Social plugin for WordPress is vulnerable to …6.1
- CVE-2025-60550D-Link DIR600L Ax FW116WWb01 was discovered to contain a buf…7.5
- CVE-2025-60551D-Link DIR600L Ax FW116WWb01 was discovered to contain a buf…7.5
Are you affected by CVE-2025-60542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
