CVE-2026-29793 | Feathersjs up to 5.0.41 getObjectId data query logic injection (GHSA-p9xr-7p9p-gpqx)
A vulnerability categorized as critical has been discovered in Feathersjs up to 5.0.41. The impacted element is the function getObjectId. The manipulation results in improper neutralization of special elements in data query logic.
This vulnerability was named CVE-2026-29793. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.