Live data from GitHub and npm, updated daily.
Data last fetched: 2026-06-29
4 active CVEs reported via OSV.dev
Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings
Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`.
Get SLA-backed support, security patches, and direct access to senior engineers for Kysely — without relying on volunteer maintainers.