PT-2026-108147 · Mariadb · Mariadb-Connector-Nodejs

CVE-2026-107384

·

Published

2026-10-08

·

Updated

2026-10-09

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MariaDB Connector/Node.js versions 3.2.0 through 3.2.4 MariaDB Connector/Node.js versions 3.3.x prior to 3.3.4 MariaDB Connector/Node.js versions 3.4.x prior to 3.4.7 MariaDB Connector/Node.js versions 3.5.x prior to 3.5.4
Description When the non-default permitSetMultiParamEntries option is enabled, objects passed as query parameters are expanded into a SQL SET clause where keys are treated as column names. The implementation failed to call the escapeId() function for these keys, allowing a key containing a backtick to close the quoted identifier. This enables an attacker to inject arbitrary SQL, potentially updating unauthorized columns such as roles, balances, or passwords, with the privileges of the database user. This issue occurs because the identifier escaper was bypassed in three specific code paths.
Recommendations Update MariaDB Connector/Node.js to version 3.2.5. Update MariaDB Connector/Node.js to version 3.3.4. Update MariaDB Connector/Node.js to version 3.4.7. Update MariaDB Connector/Node.js to version 3.5.4. Disable the permitSetMultiParamEntries option. Validate object keys against an allow-list of column names before passing them to the query() function.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107384
GHSA-V6PJ-GXXW-PHFW

Affected Products

Mariadb-Connector-Nodejs