I face the same problem it's maybe because you are sending the query as a string not as an object so if you are sending a string it won't be sanitized