Knexjs maintains a query-building library for Node.js that abstracts database interactions across multiple SQL and NoSQL backends, making it a widely adopted component in JavaScript application stacks despite its narrow product scope. The observed vulnerability signal centers on SQL injection risks within the query-construction layer, reflecting the inherent challenge of safely composing dynamic SQL statements across diverse database targets. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knexjs over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10757CRITICAL knex.js versions before 0.19.5 are vulnerable to SQL Injection attack. Identifiers are escaped incorrectly as part of the MSSQL dialect, allowing attackers to craft a malicious que | Oct 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2016-20018HIGH Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query. | Dec 19, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knexjs.
Media articles that mention a CVE ID that affects a product developed by Knexjs — matched by CVE ID, not by vendor name.