Description
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value before AbstractSqlPlatform.getOrderByExpression concatenates it into an ORDER BY clause. Applications that bind attacker-controlled request data to the direction in em.find(), em.findOne(), em.findAndCount(), QueryBuilder.orderBy(), or QueryBuilderHelper.getQueryOrderFromObject() can permit a raw SQL fragment that performs blind or boolean extraction of data available to the database account. The BaseMySqlPlatform and MsSqlPlatform fallthrough paths have the same behavior, affecting SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers, while MongoDB is not affected. This issue is fixed in versions 6.6.16 and 7.1.7.
Published: 2026-09-16
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection enabling data extraction via ORDER BY clause
Action: Patch immediately
AI Analysis

Impact

The vulnerability arises when MikroORM's SQL layer accepts an untrusted value for the ORDER BY direction and injects it directly into a query string. Because the direction field is not restricted, an attacker can supply raw SQL fragments that are executed by the database. This can result in blind or boolean extraction of sensitive information within the database account's privileges, compromising confidentiality of database contents.

Affected Systems

Vendors and products affected are MikroORM for Node.js. Versions prior to 6.6.16 and 7.1.7 are vulnerable. The issue impacts query builders and repository find methods that use the direction parameter in SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers; MongoDB drivers are unaffected.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as medium severity. Its EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, suggesting no publicly known large-scale exploitation. Attackers would need to target applications that expose the order direction parameter to user-controlled data, typically via crafted HTTP requests or API calls. Successful exploitation requires the application to be using one of the vulnerable versions and to expose the affected query paths.

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MikroORM to version 6.6.16 or later, or 7.1.7 or later
  • Validate the order direction value on the server side and constrain it to the accepted set (e.g., ASC or DESC) before it is passed to the ORM
  • Review all code that builds dynamic ORDER BY clauses and replace user‑controlled inputs with parameterized or whitelisted values

Generated by OpenCVE AI on September 18, 2026 at 01:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
First Time appeared Mikro-orm
Mikro-orm mikro-orm
Vendors & Products Mikro-orm
Mikro-orm mikro-orm

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to 6.6.16 and 7.1.7, the shared SQL layer validates the field key of an orderBy clause but does not validate its direction value before AbstractSqlPlatform.getOrderByExpression concatenates it into an ORDER BY clause. Applications that bind attacker-controlled request data to the direction in em.find(), em.findOne(), em.findAndCount(), QueryBuilder.orderBy(), or QueryBuilderHelper.getQueryOrderFromObject() can permit a raw SQL fragment that performs blind or boolean extraction of data available to the database account. The BaseMySqlPlatform and MsSqlPlatform fallthrough paths have the same behavior, affecting SQLite, PostgreSQL, MySQL, MariaDB, MSSQL, libSQL, and Oracle drivers, while MongoDB is not affected. This issue is fixed in versions 6.6.16 and 7.1.7.
Title MikroORM: SQL injection via unvalidated order direction in orderBy
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Mikro-orm Mikro-orm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-16T17:42:01.623Z

Reserved: 2026-09-02T18:12:13.534Z

Link: CVE-2026-84993

cve-icon Vulnrichment

Updated: 2026-09-16T17:41:58.182Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T17:18:15.423

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-84993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T06:00:04Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')