CVE-2025-32020 CRITICAL

CVE-2025-32020: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in crud-query-parser

Vendor Guichaguri
Product crud-query-parser
Weakness CWE-89 · SQLi
Published April 8, 2025
Last update April 8, 2025

CVSS base score

9.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper neutralization of the order/sort parameter in the TypeORM adapter, which allows SQL injection. You are impacted by this vulnerability if you are using the TypeORM adapter, ordering is enabled and you have not set-up a property filter. This vulnerability is fixed in 0.1.0.

Key dates

02Disclosure timeline

April 8, 2025 CVE published
April 8, 2025 Record updated