All the vulnerabilities related to the version 0.9.1 of the package
SQL Injection in mysql
Versions of mysql
prior to 2.0.0-alpha8 are affected by a SQL Injection vulnerability in the mysql.escape()
function, which does not properly escape object keys.
Update to version 2.0.0-alpha8 or later.