sqlite3
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting sqlite3page 1 of 1
- CVE-2022-21227HIGHCVSS 7.5EG 7.5✓ Fixed in 5.0.32022-05-01
The package sqlite3 before 5.0.3 are vulnerable to Denial of Service (DoS) which will invoke the toString function of the passed parameter. If passed an invalid Function object it will throw and crash the V8 engine.
- CVE-2022-43441HIGHCVSS 8.1EG 8.1✓ Fixed in 5.1.52023-03-16
A code execution vulnerability exists in the Statement Bindings functionality of Ghost Foundation node-sqlite3 5.1.1. A specially-crafted Javascript file can lead to arbitrary code execution. An attacker can provide malicious input to trig…
Check whether sqlite3 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for sqlite3 CVEs against the assets you own.
Start Free Scan →