CVE-2026-39356 | drizzle-team drizzle-orm up to 0.45.1 escapeName sql injection (GHSA-gpj5-g38j-94v9)
A vulnerability classified as critical was found in drizzle-team drizzle-orm up to 0.45.1. This impacts the function escapeName. Executing a manipulation can lead to sql injection.
This vulnerability is handled as CVE-2026-39356. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.