StackRadar

CVE-2026-30951

High

Advisory

Published 11 Mar 2026In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.004
36th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
27
of 17,781 indexed, latest versions
Container images
20
deployed by those charts
Fix available
1 of 1
affected package

Sequelize v6 Vulnerable to SQL Injection via JSON Column Cast Type

Carried by container images the latest versions of 27 of 17,781 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
sequelizenpm6.3.3, 6.5.1, 6.6.2, 6.9.0+10 more6.37.820
OSV records
GHSA-6457-6jrx-69cr

Charts affected

27 by stars
ChartLatestAffected imagesRadar Score
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.8

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
sequelize@6.37.3
6.37.8

Open the chart page →

5,352
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
sequelize@6.37.3
6.37.8

Open the chart page →

7,450
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
sequelize@6.9.0
6.37.8

Open the chart page →

2,449
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.8

Open the chart page →

1,722
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.8

Open the chart page →

1,722
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.8

Open the chart page →

1,722
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.8

Open the chart page →

27,550
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.8

Open the chart page →

24,656
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.8

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.8

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
sequelize@6.19.0
6.37.8

Open the chart page →

27,096
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
sequelize@6.29.3
6.37.8

Open the chart page →

3,159
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
sequelize@6.9.0
6.37.8

Open the chart page →

2,172
contentbridgeglenndehaanVerified publisher1.1.01 of 1See more

contentbridge glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
glenndehaan/contentbridge:latest99b9e4f73848
sequelize@6.29.3
6.37.8

Open the chart page →

1,000
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sequelize@6.35.2
6.37.8

Open the chart page →

2,350
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
sequelize@6.6.2
6.37.8

Open the chart page →

3,397
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
sequelize@6.18.0
6.37.8

Open the chart page →

29,588
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
sequelize@6.3.3
6.37.8

Open the chart page →

6,684
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
sequelize@6.5.1
6.37.8

Open the chart page →

28,484
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sequelize@6.35.2
6.37.8

Open the chart page →

6,282
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.8

Open the chart page →

1,722
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
sequelize@6.32.1
6.37.8

Open the chart page →

5,582
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.8

Open the chart page →

4,431
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
sequelize@6.11.0
6.37.8

Open the chart page →

2,121
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
sequelize@6.13.0
6.37.8

Open the chart page →

3,576
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-30951.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
sequelize@6.37.7
6.37.8

Open the chart page →

5,984

Container images carrying it

20 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.8
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.8
4
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.8
2
arturisimo/server-urjc:v1.0d8dc4430531e
sequelize@6.19.0
6.37.8
1
catalysm/csmm:latestf003b35f54d9
sequelize@6.13.0
6.37.8
1
codetogether/codetogether:latest4348c8a38752
sequelize@6.37.3
6.37.8
1
fiware/idm:8.3.3a1b6ed4ae84f
sequelize@6.29.3
6.37.8
1
glenndehaan/contentbridge:latest99b9e4f73848
sequelize@6.29.3
6.37.8
1
hugohg34/server:0.0.2503e5d8960ff
sequelize@6.18.0
6.37.8
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
sequelize@6.32.1
6.37.8
1
mozilla/sentencecollector:2.0.91da6ff5c4895
sequelize@6.3.3
6.37.8
1
outlinewiki/outline:0.82.0494dfb9249a6
sequelize@6.37.3
6.37.8
1
pawelmalak/flame:2.1.193e7b0abb603
sequelize@6.9.0
6.37.8
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
sequelize@6.9.0
6.37.8
1
sigp/siren:v3.0.42c219b04758e
sequelize@6.37.7
6.37.8
1
slagattollas/server-practica:latest6dd8ead8e2b1
sequelize@6.5.1
6.37.8
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
sequelize@6.11.0
6.37.8
1
sqlpad/sqlpad:6.7d3d2f430dffd
sequelize@6.6.2
6.37.8
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sequelize@6.35.2
6.37.8
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sequelize@6.35.2
6.37.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.