Sequelize is a promise-based Node.js ORM tool for Postgres, MySQL, MariaDB, SQLite, Microsoft SQL Server, Amazon Redshift and Snowflake’s Data Cloud. It features solid transaction support, relations, eager and lazy loading, read replication and more.
sequelize has critical vulnerabilities — do not use
Update to >= 7.0.0-alpha.20 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2023-22580 | Sequelize information disclosure vulnerability | 7.0.0-alpha.20 |
| critical | CVE-2023-22579 | Unsafe fall-through in getWhereConditions | 7.0.0-alpha.20 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/sequelizeFirst published · 2011-05-03T17:08:41.163Z
Last updated · 2026-03-07T18:44:43.419Z