OsVault/npm/kysely
npm

kysely

3 known vulnerabilities · 0 critical · 0 high

CVE-2026-33468

Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings

Published Mar 20, 2026
CVE-2026-32763

SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.

Published Mar 18, 2026
CVE-2026-33442

Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.

Published Mar 20, 2026
Check your entire dependency tree at onceRun dependency scan →