Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v6pj-gxxw-phfw | MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries) |
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mariadb-corporation
Mariadb-corporation mariadb-connector-nodejs |
|
| Vendors & Products |
Mariadb-corporation
Mariadb-corporation mariadb-connector-nodejs |
Thu, 08 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. | |
| Title | MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries) | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T18:32:30.156Z
Reserved: 2026-10-07T21:07:54.988Z
Link: CVE-2026-107384
No data.
Status : Awaiting Analysis
Published: 2026-10-08T19:17:00.990
Modified: 2026-10-08T20:25:00.647
Link: CVE-2026-107384
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:15:06Z
-
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Github GHSA