PT-2026-108148 · Mariadb · Mariadb-Connector-Nodejs

CVE-2026-107385

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions MariaDB Connector/Node.js versions prior to 3.2.5 MariaDB Connector/Node.js versions prior to 3.3.4 MariaDB Connector/Node.js versions prior to 3.4.7 MariaDB Connector/Node.js versions prior to 3.5.4
Description Text-protocol escaping fails to honor the session's NO BACKSLASH ESCAPES mode, including within the Connection.escape() function. In this mode, the backslash is treated as an ordinary character rather than an escape character. Because the connector always prefixes quotes with a backslash, an attacker-controlled placeholder value can prematurely close the SQL string literal, allowing the injection of arbitrary SQL commands with the application's database privileges. This occurs when NO BACKSLASH ESCAPES is enabled server-wide, via connector initialization options, or through a SET sql mode command. The execute() and batch() functions are not affected as they utilize binary protocols.
Recommendations Update to version 3.2.5 or later. Update to version 3.3.4 or later. Update to version 3.4.7 or later. Update to version 3.5.4 or later. As a temporary workaround, use the execute() or batch() functions instead of text-protocol escaping. As a temporary workaround, disable the NO BACKSLASH ESCAPES mode.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107385
GHSA-R3RV-JM3R-62Q2

Affected Products

Mariadb-Connector-Nodejs