@@ -430,14 +430,14 @@ the community they pose.
430430
431431* Examples of scenarios that are ** not** Node.js vulnerabilities:
432432 * Allowing untrusted users to register SQLite user-defined functions via
433- ` node:sqlite ` (` DatabaseSync ` ) that can perform arbitrary operations
433+ ` node:sqlite ` (` Database ` ) that can perform arbitrary operations
434434 (e.g., closing database connections during query execution, causing crashes
435435 or use-after-free conditions).
436436 * Loading SQLite extensions using the ` allowExtension ` option in
437- ` DatabaseSync ` — this option must be explicitly set to ` true ` by the
437+ ` Database ` — this option must be explicitly set to ` true ` by the
438438 application, and enabling it is the application operator's responsibility.
439439 * Using ` node:sqlite ` built-in SQL functions or pragmas (e.g.,
440- ` ATTACH DATABASE ` ) to read or write files — ` DatabaseSync ` operates with
440+ ` ATTACH DATABASE ` ) to read or write files — ` Database ` operates with
441441 the same file-system access as the process itself, and it is the
442442 application's responsibility to restrict what SQL is executed.
443443 * Exposing ` child_process.exec() ` or similar APIs to untrusted users without
@@ -524,7 +524,7 @@ The following are **not** vulnerabilities in Node.js:
524524 responsibility. The permission model does not restrict how Node.js behaves
525525 when the operator intentionally configures it.
526526
527- * ** ` node:sqlite ` and the permission model** : ` DatabaseSync ` operates with the
527+ * ** ` node:sqlite ` and the permission model** : ` Database ` operates with the
528528 same file-system privileges as the process. Using SQL pragmas or built-in
529529 SQLite mechanisms (e.g., ` ATTACH DATABASE ` ) to access files does not bypass
530530 the permission model — the permission model does not intercept SQL-level
0 commit comments