ParentFull threadavelino·pREST is not vulnerable to SQL injection, recommend you run tests Check access level (permissions) in https://github.com/nuveo/prest#table-permissionsView on HN