PT-2026-108148 · Mariadb · Mariadb-Connector-Nodejs
CVE-2026-107385
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MariaDB Connector/Node.js versions prior to 3.2.5
MariaDB Connector/Node.js versions prior to 3.3.4
MariaDB Connector/Node.js versions prior to 3.4.7
MariaDB Connector/Node.js versions prior to 3.5.4
Description
Text-protocol escaping fails to honor the session's
NO BACKSLASH ESCAPES mode, including within the Connection.escape() function. In this mode, the backslash is treated as an ordinary character rather than an escape character. Because the connector always prefixes quotes with a backslash, an attacker-controlled placeholder value can prematurely close the SQL string literal, allowing the injection of arbitrary SQL commands with the application's database privileges. This occurs when NO BACKSLASH ESCAPES is enabled server-wide, via connector initialization options, or through a SET sql mode command. The execute() and batch() functions are not affected as they utilize binary protocols.Recommendations
Update to version 3.2.5 or later.
Update to version 3.3.4 or later.
Update to version 3.4.7 or later.
Update to version 3.5.4 or later.
As a temporary workaround, use the
execute() or batch() functions instead of text-protocol escaping.
As a temporary workaround, disable the NO BACKSLASH ESCAPES mode.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mariadb-Connector-Nodejs