CVE-2026-107384
Awaiting Analysis Awaiting Analysis - Queue

SQL Injection in MariaDB Connector/Node.js

Vulnerability report for CVE-2026-107384, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
mariadb-corporation mariadb-connector-nodejs >= 3.2.0, < 3.2.5
mariadb-corporation mariadb-connector-nodejs >= 3.3.0, < 3.3.4
mariadb-corporation mariadb-connector-nodejs >= 3.4.0, < 3.4.7
mariadb-corporation mariadb-connector-nodejs >= 3.5.0-rc.0, < 3.5.4

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a SQL injection vulnerability in MariaDB Connector/Node.js affecting versions 3.2.0 to 3.2.5, 3.3.0 to 3.3.4, 3.4.0 to 3.4.7, and 3.5.0-rc.0 to 3.5.3. It occurs when the permitSetMultiParamEntries option is enabled. Attackers can inject malicious SQL by including backticks in object keys, which are then used as column names in SET clauses without proper escaping. This allows unauthorized access to sensitive data or manipulation of database queries.

Detection Guidance

Check if your MariaDB Connector/Node.js version is affected by running: npm list mariadb-connector-nodejs. If the version is >= 3.2.0 and < 3.2.5, >= 3.3.0 and < 3.3.4, >= 3.4.0 and < 3.4.7, or >= 3.5.0-rc.0 and < 3.5.4, the system is vulnerable.

Impact Analysis

An attacker could exploit this to read or modify columns the application did not intend to expose, such as passwords, financial data, or user roles. They could also append arbitrary SQL commands to queries, potentially leading to full database compromise. The impact depends on the application's database permissions and the data stored.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive personal data, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. Organizations using affected versions may face compliance violations, regulatory penalties, and reputational damage if exploited.

Mitigation Strategies
  • Upgrade MariaDB Connector/Node.js to version 3.2.5, 3.3.4, 3.4.7, or 3.5.4 or later.
  • If upgrading is not immediately possible, disable the permitSetMultiParamEntries option in your application configuration.
  • Validate all object keys passed to SQL queries against an allow-list of permitted column names before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107384. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart