CVE-2026-34220: MikroORM is vulnerable to SQL Injection via specially crafted object
MikroORM versions <= 6.6.9 and <= 7.0.5 are vulnerable to SQL injection when specially crafted objects are interpreted as raw SQL query fragments.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34220 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →