Sploitus

CVE-2026-34220

1 known exploit for CVE-2026-34220

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to versions 6.6.10 and 7.0.6, there is a SQL injection vulnerability when specially crafted objects are interpreted as raw SQL query fragments. This issue has been patched in versions 6.6.10 and 7.0.6.

Affected products
Mikroorm
Mikro-orm Mikroorm
< 6.6.10, 7.0.6
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (36th percentile)
Weakness
CWE-89
NVD status
Analyzed
Published
2026-03-31
CVE-2026-34220 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2026-34220

Proof-of-concept code and exploit modules indexed by Sploitus