Kysely is a lightweight, type-safe SQL query builder for JavaScript and TypeScript that abstracts database interactions across multiple backend systems. The vulnerability signal centers on SQL injection risks arising from query construction and parameterization handling in this database abstraction layer. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kysely over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33468HIGH Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeStringLiteral()` only escapes single quotes by doubling them (` | Mar 26, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-33442HIGH Kysely is a type-safe TypeScript SQL query builder. In versions 0.28.12 and 0.28.13, the `sanitizeStringLiteral` method in Kysely's query compiler escapes single quotes (`'` → `''` | Mar 26, 2026 | 8.1 | 28 | NO | NO |
CVE-2026-32763HIGH Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. T | Mar 20, 2026 | 8.2 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kysely.
Media articles that mention a CVE ID that affects a product developed by Kysely — matched by CVE ID, not by vendor name.