StackRadar

CVE-2026-69240

Critical

Advisory

Published 3 Aug 2026In the index since 6 Sept 2026
Severity
Critical
worst across findings
CVSS
9.8
base score, highest
EPSS
0.004
33rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
39
of 17,781 indexed, latest versions
Container images
30
deployed by those charts
Fix available
1 of 1
affected package

Sequelize: SQL Injection (Oracle DB)

Carried by container images the latest versions of 39 of 17,781 indexed charts deploy, on 30 images.

Affected packageAffected versionsFixed inImages
sequelizenpm1.7.11, 2.0.0-beta.0, 4.44.4, 5.21.1+17 more6.37.430
OSV records
GHSA-v8fg-2rw7-q452

Charts affected

39 by stars
ChartLatestAffected imagesRadar Score
outlineoutline0.0.91 of 4See more

outline outline 0.0.9

1 of the 4 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.4

Open the chart page →

4,431
outlinekubitodevVerified publisher1.2.21 of 4See more

outline kubitodev 1.2.2

1 of the 4 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
outlinewiki/outline:0.82.0494dfb9249a6
sequelize@6.37.3
6.37.4

Open the chart page →

5,352
hedgedocadfinisVerified publisher0.6.11 of 2See more

hedgedoc adfinis 0.6.1

1 of the 2 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sequelize@5.22.5
6.37.4

Open the chart page →

2,938
lighthouse-cicowboysysopVerified publisher9.0.01 of 1See more

lighthouse-ci cowboysysop 9.0.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
patrickhulce/lhci-server:0.8.174b4b6a3954d
sequelize@4.44.4
6.37.4

Open the chart page →

2,213
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
sequelize@6.37.3
6.37.4

Open the chart page →

7,450
hedgedocrobertobochetVerified publisher1.4.01 of 1See more

hedgedoc robertobochet 1.4.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sequelize@5.22.5
6.37.4

Open the chart page →

977
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
sequelize@5.22.3
6.37.4

Open the chart page →

2,851
flamerlex0.3.01 of 1See more

flame rlex 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
pawelmalak/flame:2.1.193e7b0abb603
sequelize@6.9.0
6.37.4

Open the chart page →

2,449
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.4

Open the chart page →

1,722
audiobookshelfcharts-derwitt-devVerified publisher1.1.01 of 1See more

audiobookshelf charts-derwitt-dev 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.4

Open the chart page →

1,722
audiobookshelfchristianhuthVerified publisher2.4.01 of 1See more

audiobookshelf christianhuth 2.4.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.4

Open the chart page →

1,722
eoloplannerdfa-amm-eoloplannerVerified publisher0.1.01 of 7See more

eoloplanner dfa-amm-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.4

Open the chart page →

27,550
eoloplannerdreyg-jescribanob-chart-eoloplanner0.1.01 of 7See more

eoloplanner dreyg-jescribanob-chart-eoloplanner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.4

Open the chart page →

24,656
eolicplantseolicplantsVerified publisher0.1.01 of 7See more

eolicplants eolicplants 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.4

Open the chart page →

27,291
eoloplanner-mcaeoloplanner-mcaVerified publisher0.1.01 of 7See more

eoloplanner-mca eoloplanner-mca 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.4

Open the chart page →

27,256
eolo-plannereolo-planner-repo0.1.01 of 7See more

eolo-planner eolo-planner-repo 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
arturisimo/server-urjc:v1.0d8dc4430531e
sequelize@6.19.0
6.37.4

Open the chart page →

27,096
hedgedocernail-hedgedoc5.0.01 of 1See more

hedgedoc ernail-hedgedoc 5.0.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
sequelize@5.22.5
6.37.4

Open the chart page →

1,755
keyrockfiware0.8.71 of 1See more

keyrock fiware 0.8.7

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
fiware/idm:8.3.3a1b6ed4ae84f
sequelize@6.29.3
6.37.4

Open the chart page →

3,159
flamegabe565Verified publisher0.6.01 of 1See more

flame gabe565 0.6.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
pawelmalak/flame:multiarch2.3.19f88b17692a0
sequelize@6.9.0
6.37.4

Open the chart page →

2,172
contentbridgeglenndehaanVerified publisher1.1.01 of 1See more

contentbridge glenndehaan 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
glenndehaan/contentbridge:latest99b9e4f73848
sequelize@6.29.3
6.37.4

Open the chart page →

1,000
iofoghelm-chartsVerified publisher0.1.11 of 3See more

iofog helm-charts 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
sequelize@5.21.1
6.37.4

Open the chart page →

24,161
audiobookshelfk8s-home-lab-repo2.0.11 of 1See more

audiobookshelf k8s-home-lab-repo 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sequelize@6.35.2
6.37.4

Open the chart page →

2,350
sqlpadkronkltdVerified publisher0.1.01 of 1See more

sqlpad kronkltd 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
sqlpad/sqlpad:6.7d3d2f430dffd
sequelize@6.6.2
6.37.4

Open the chart page →

3,397
eoloplantmca-eoloplaner0.1.01 of 7See more

eoloplant mca-eoloplaner 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
hugohg34/server:0.0.2503e5d8960ff
sequelize@6.18.0
6.37.4

Open the chart page →

29,588
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
sequelize@6.3.3
6.37.4

Open the chart page →

6,684
example-dev-toolsnoygal0.2.82 of 3See more

example-dev-tools noygal 0.2.8

2 of the 3 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
linuxserver/cloud9:latest45c5fe102ff3
sequelize@2.0.0-beta.0
6.37.4
linuxserver/codimd:latestb801bbcf6386
sequelize@5.22.3
6.37.4

Open the chart page →

27,465
flomesh-consoleopenshift0.70.0-30-ubi81 of 2See more

flomesh-console openshift 0.70.0-30-ubi8

1 of the 2 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sequelize@5.22.4
6.37.4

Open the chart page →

9,968
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
sequelize@5.21.13
6.37.4

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
sequelize@6.5.1
6.37.4

Open the chart page →

28,484
relfinder-reformedrelfinderreformed2.0.01 of 2See more

relfinder-reformed relfinderreformed 2.0.0

1 of the 2 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sequelize@6.35.2
6.37.4

Open the chart page →

6,282
audiobookshelfrubxkubeVerified publisher0.1.31 of 1See more

audiobookshelf rubxkube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.4

Open the chart page →

1,722
unifi-protectschichtelVerified publisher0.10.11 of 1See more

unifi-protect schichtel 0.10.1

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
sequelize@6.32.1
6.37.4

Open the chart page →

5,582
hedgedocschmitzis0.1.121 of 1See more

hedgedoc schmitzis 0.1.12

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
sequelize@5.22.5
6.37.4

Open the chart page →

3,118
outlineschmitzis0.0.81 of 4See more

outline schmitzis 0.0.8

1 of the 4 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.4

Open the chart page →

4,431
hedgedocsi-gitops0.12.31 of 2See more

hedgedoc si-gitops 0.12.3

1 of the 2 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sequelize@5.22.5
6.37.4

Open the chart page →

2,638
alertmanager-to-alerta-botsomeblackmagic0.2.01 of 1See more

alertmanager-to-alerta-bot someblackmagic 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
sequelize@6.11.0
6.37.4

Open the chart page →

2,121
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
sequelize@1.7.11
6.37.4

Open the chart page →

3,827
csmmth-chartsVerified publisher0.1.01 of 3See more

csmm th-charts 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
catalysm/csmm:latestf003b35f54d9
sequelize@6.13.0
6.37.4

Open the chart page →

3,576
hedgedocvista0.1.11 of 1See more

hedgedoc vista 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-69240.

Container imageDigestPackageFixed in
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
sequelize@5.22.5
6.37.4

Open the chart page →

3,118

Container images carrying it

30 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
oscarsotosanchez/server:v1.06e2e1279126b
sequelize@6.5.1
6.37.4
4
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
sequelize@6.35.2
6.37.4
4
quay.io/hedgedoc/hedgedoc:1.12.089bd85d7817f
sequelize@5.22.5
6.37.4
3
outlinewiki/outline:0.69.1d060dcd8f9aa
sequelize@6.29.0
6.37.4
2
quay.io/hedgedoc/hedgedoc:1.9.4e09967519a1d
sequelize@5.22.5
6.37.4
2
arturisimo/server-urjc:v1.0d8dc4430531e
sequelize@6.19.0
6.37.4
1
catalysm/csmm:latestf003b35f54d9
sequelize@6.13.0
6.37.4
1
codetogether/codetogether:latest4348c8a38752
sequelize@6.37.3
6.37.4
1
fiware/idm:8.3.3a1b6ed4ae84f
sequelize@6.29.3
6.37.4
1
glenndehaan/contentbridge:latest99b9e4f73848
sequelize@6.29.3
6.37.4
1
hugohg34/server:0.0.2503e5d8960ff
sequelize@6.18.0
6.37.4
1
linuxserver/cloud9:latest45c5fe102ff3
sequelize@2.0.0-beta.0
6.37.4
1
linuxserver/codimd:latestb801bbcf6386
sequelize@5.22.3
6.37.4
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
sequelize@6.32.1
6.37.4
1
mozilla/sentencecollector:2.0.91da6ff5c4895
sequelize@6.3.3
6.37.4
1
outlinewiki/outline:0.82.0494dfb9249a6
sequelize@6.37.3
6.37.4
1
patrickhulce/lhci-server:0.8.174b4b6a3954d
sequelize@4.44.4
6.37.4
1
pawelmalak/flame:2.1.193e7b0abb603
sequelize@6.9.0
6.37.4
1
pawelmalak/flame:multiarch2.3.19f88b17692a0
sequelize@6.9.0
6.37.4
1
phntom/codimd:2.4.31b9aafbb62e6
sequelize@5.21.13
6.37.4
1
slagattollas/server-practica:latest6dd8ead8e2b1
sequelize@6.5.1
6.37.4
1
someblackmagic/alertmanager-to-alerta-bot:latest78bf43744ea5
sequelize@6.11.0
6.37.4
1
sqlpad/sqlpad:6.7d3d2f430dffd
sequelize@6.6.2
6.37.4
1
zooz/predator:1.6f491d1f7a865
sequelize@5.22.3
6.37.4
1
ghcr.io/advplyr/audiobookshelf:2.32.1a52dc5db694a
sequelize@6.35.2
6.37.4
1
ghcr.io/woodenmaiden/relfinderreformedapi:1.1.20708d30433d4
sequelize@6.35.2
6.37.4
1
quay.io/ctrontesting/iofog-controller:latest10df27bc5560
sequelize@5.21.1
6.37.4
1
quay.io/flomesh/flomesh-console-ubi8:0.70.0-30ce6938ff6709
sequelize@5.22.4
6.37.4
1
quay.io/hedgedoc/hedgedoc:1.10.8abdb6b08815d
sequelize@5.22.5
6.37.4
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
sequelize@1.7.11
6.37.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.