Feather-Sequelize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of application.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-2982…