When request JSON is passed into a Sequelize where clause, attacker-controlled operator keys ($gt, $ne, $like) alter query logic—authentication bypass and data disclosure without raw SQL.
sequelize.query() runs raw SQL against the backend; concatenating request data into it instead of using replacements or bind yields SQL injection in Node.js apps.
Mixing :replacements with string concatenation, or feeding attacker-controlled identifiers through replacements, reintroduces SQL injection in Sequelize raw queries.
We use cookies to enhance your experience. Learn more