Back to database
Act now81High8.1VulnerabilityCVE-2026-107384No patch link observed

CVE-2026-107384 — MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases.

Published Oct 8, 2026, 07:17 PM UTCIngested 5h agoSource NVD(cve-db)CVE-2026-107384

Description

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
8.1

High severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

High

Confidentiality

I

High

Integrity

A

High

Availability

Affected

Vendor
npm
Product
mariadb

Versions

  • pkg:npm/mariadb >= 3.2.0, < 3.2.5
  • pkg:npm/mariadb >= 3.3.0, < 3.3.4
  • pkg:npm/mariadb >= 3.4.0, < 3.4.7
  • pkg:npm/mariadb >= 3.5.0-rc.0, < 3.5.4

Stated as the source expressed them.