Skip to content

Upgrade pg-promise to 11.5.5 to fix CVE-2025-29744#19

Merged
saffronjam merged 1 commit intomasterfrom
fix/cve-2025-29744-pg-promise-sql-injection
Dec 16, 2025
Merged

Upgrade pg-promise to 11.5.5 to fix CVE-2025-29744#19
saffronjam merged 1 commit intomasterfrom
fix/cve-2025-29744-pg-promise-sql-injection

Conversation

@saffronjam
Copy link

Fixes SQL injection vulnerability caused by improper handling of negative numbers in pg-promise versions prior to 11.5.5.

https://osv.dev/GHSA-ff9h-848c-4xfj

@saffronjam saffronjam force-pushed the fix/cve-2025-29744-pg-promise-sql-injection branch from ab911bb to 5da2f39 Compare December 15, 2025 15:38
Fixes SQL injection vulnerability caused by improper handling of
negative numbers in pg-promise versions prior to 11.5.5.

https://osv.dev/GHSA-ff9h-848c-4xfj
@saffronjam saffronjam force-pushed the fix/cve-2025-29744-pg-promise-sql-injection branch from 5da2f39 to d28a9b4 Compare December 15, 2025 15:42
@saffronjam saffronjam requested a review from ecksun December 15, 2025 15:49
@saffronjam saffronjam merged commit f751556 into master Dec 16, 2025
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants