Skip to main content

CVE-2026-107384: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in mariadb-corporation mariadb-connector-nodejs

0
High
Published: 10/08/2026 (10/08/2026, 19:42:23 UTC)
Source: CVE Database V5
Vendor/Project: mariadb-corporation
Product: mariadb-connector-nodejs

Description

### Description With the non-default permitSetMultiParamEntries option enabled, an object passed as a query parameter is expanded into a SET clause, each key becoming a column name. The three code paths implementing that expansion built the backtick-quoted identifier by hand and wrote the key out unescaped, while only the value was escaped. A key containing a backtick therefore closed the identifier, and the remainder of the key was parsed as SQL. The connector's own identifier escaper (escapeId, which correctly doubles backticks) existed but was not called from any of the three sites. This is an incomplete fix of GitHub issue #252, which corrected escapeId itself in 2023 but left these hand-built call sites unchanged. ### Impact An application that enables permitSetMultiParamEntries and passes an object with attacker-influenced keys into a statement such as conn.query('UPDATE users SET ? WHERE id = ?', [body, id]) allows the caller to write columns the application never intended to expose — a role, balance or password column — and to append arbitrary SQL to the statement, since the injected text is not confined to an assignment. Exposure requires the option to be enabled: it is off by default, and with it off the object is serialised and escaped as a single string literal, so the key never reaches the SQL grammar. Passing a request body into this API is, however, the ordinary reason to enable the option. An application that enables it is asking for keys to become column names, not for keys to become arbitrary SQL. ### Resolution All three expansion sites now route the key through the identifier escaper, doubling backticks before writing the column name. The feature is unchanged for legitimate keys, including reserved words. ### Workarounds Disable permitSetMultiParamEntries (the default), or validate object keys against an allow-list of column names before passing them to query(), until upgraded. ### Credit Reported by fg0x0.

CVSS v3.1

Score 8.1high

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected software

mariadb-corporation

mariadb-connector-nodejs

Affected versions
>=3.2.0 <3.2.5>=3.3.0 <3.3.4>=3.4.0 <3.4.7>=3.5.0-rc.0 <3.5.4

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/08/2026, 20:38:09 UTC

Technical Analysis

MariaDB Connector/Node.js versions >=3.2.0 <3.2.5, >=3.3.0 <3.3.4, >=3.4.0 <3.4.7, and >=3.5.0-rc.0 <3.5.4 allow SQL injection via the permitSetMultiParamEntries option. When enabled, this option permits passing objects whose keys are expanded into SQL SET clauses without proper escaping (escapeId). An attacker can craft keys containing backticks to close quoted identifiers and inject arbitrary SQL commands, leading to unauthorized updates or SQL execution with the database user's privileges. The vulnerability is mitigated by disabling this option (default) or upgrading to fixed versions.

Potential Impact

An attacker can exploit this vulnerability to perform SQL injection attacks, potentially modifying database columns that the application did not intend to expose and executing arbitrary SQL commands with the privileges of the database user. This can lead to data integrity compromise, unauthorized data modification, and potentially full database compromise depending on the privileges of the database user.

Mitigation Recommendations

This vulnerability is fixed in MariaDB Connector/Node.js versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4. Users should upgrade to these versions or later. Additionally, the permitSetMultiParamEntries option is disabled by default; ensuring this option remains disabled prevents exposure to this vulnerability. No other mitigation is required if the option is not enabled.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-10-07T21:07:54.988Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6ac7f4262cdf04f6563004d3

Added to database: 10/08/2026, 19:51:02 UTC

Last enriched: 10/08/2026, 20:38:09 UTC

Last updated: 10/08/2026, 21:45:49 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses