Typeorm is a lightweight object-relational mapping (ORM) library for Node.js and TypeScript that abstracts database interactions across SQL and NoSQL backends. Its vulnerability profile centers on the single library itself and recurs through application-layer weaknesses: SQL injection arising from improper query construction, prototype pollution through unsafe property handling, and modification of assumed-immutable data structures. Current vulnerability counts and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typeorm over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33171CRITICAL The findOne function in TypeORM before 0.3.0 can either be supplied with a string or a FindOneOptions object. When input to the function is a user-controlled parsed JSON object, su | Jul 4, 2022 | 9.8 | 41 | NO | NO |
CVE-2020-8158CRITICAL Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attac | Sep 18, 2020 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typeorm.
Media articles that mention a CVE ID that affects a product developed by Typeorm — matched by CVE ID, not by vendor name.