A vulnerability was found in dresende node-sql-query 0.1.25/0.1.26/0.1.27/0.1.28. It has been classified as critical. Affected by this vulnerability is the function SelectQuery.from/SelectQuery.build in the library lib/Select.js of the component Request Parameter Handler. Performing a manipulation results in sql injection.

This vulnerability is cataloged as CVE-2026-19351. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.

Upgrading the affected component is recommended.