PT-2026-108147 · Mariadb · Mariadb-Connector-Nodejs
CVE-2026-107384
·
Published
2026-10-08
·
Updated
2026-10-09
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MariaDB Connector/Node.js versions 3.2.0 through 3.2.4
MariaDB Connector/Node.js versions 3.3.x prior to 3.3.4
MariaDB Connector/Node.js versions 3.4.x prior to 3.4.7
MariaDB Connector/Node.js versions 3.5.x prior to 3.5.4
Description
When the non-default
permitSetMultiParamEntries option is enabled, objects passed as query parameters are expanded into a SQL SET clause where keys are treated as column names. The implementation failed to call the escapeId() function for these keys, allowing a key containing a backtick to close the quoted identifier. This enables an attacker to inject arbitrary SQL, potentially updating unauthorized columns such as roles, balances, or passwords, with the privileges of the database user. This issue occurs because the identifier escaper was bypassed in three specific code paths.Recommendations
Update MariaDB Connector/Node.js to version 3.2.5.
Update MariaDB Connector/Node.js to version 3.3.4.
Update MariaDB Connector/Node.js to version 3.4.7.
Update MariaDB Connector/Node.js to version 3.5.4.
Disable the
permitSetMultiParamEntries option.
Validate object keys against an allow-list of column names before passing them to the query() function.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mariadb-Connector-Nodejs