A vulnerability categorized as critical has been discovered in Node.js up to 22.23.0/24.17.x/26.4.x. Affected is the function DatabaseSync#createTagStore of the component StatementSyncIterator. Such manipulation leads to sql injection.

This vulnerability is documented as CVE-2026-58041. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.