CVE-2026-107385: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in mariadb-corporation mariadb-connector-nodejs
Description
### Description When escaping string and binary parameters for the text protocol, the connector always escaped the quote character with a backslash, without ever consulting the session's NO_BACKSLASH_ESCAPES SQL mode. The server status flag was declared (STATUS_NO_BACKSLASH_ESCAPES) but never read. Under a server or session running with NO_BACKSLASH_ESCAPES, the backslash is an ordinary character and the quote must be escaped by doubling it. The escaped value produced by the connector therefore closed the string literal, and a value passed through a placeholder was interpreted as SQL. All text-protocol escaping entry points were affected, including Connection.escape(). ### Impact An attacker able to influence any value the application passes as a query parameter could execute arbitrary SQL with the privileges of the application's database user: read, modify or delete any data reachable by that connection. Exposure requires a deployment where NO_BACKSLASH_ESCAPES is enabled — server-wide, through the connector's sessionVariables / initSql options, or by an application-issued SET sql_mode. It is not implied by the ANSI, ORACLE or TRADITIONAL compound modes on MariaDB 11.4, so it has to be set deliberately. Where it is enabled, no unusual application code is needed: the standard placeholder API is the injection point. execute() and batch() are not affected: the binary prepared-statement and bulk protocols send parameter values out of band. ### Resolution The escaping routines now branch on the session status flag, doubling the quote and leaving the backslash untouched when NO_BACKSLASH_ESCAPES is set ### Workarounds Use execute() or batch(), or do not enable NO_BACKSLASH_ESCAPES, until upgraded. ### Credit Reported by fg0x0.
CVSS v3.1
Score 7.4high
Affected software
mariadb-corporation
mariadb-connector-nodejs
pkg:npm/mariadb-corporation/mariadb-connector-nodejsRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MariaDB Connector/Node.js improperly neutralizes special elements in SQL commands when the NO_BACKSLASH_ESCAPES mode is enabled. Specifically, text-protocol escaping always prefixes quotes with a backslash and ignores the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). Since in this mode the backslash is treated as a normal character, an attacker can craft input that closes the SQL string literal and injects arbitrary SQL commands with the application's database privileges. This vulnerability affects versions prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4. The execute() and batch() methods, which use binary protocols, are not vulnerable. The vulnerability is fixed in the stated versions.
Potential Impact
An attacker can exploit this vulnerability to perform SQL injection attacks, potentially executing arbitrary SQL commands with the privileges of the application using the MariaDB Connector/Node.js. This can lead to unauthorized data manipulation or compromise of the database integrity and availability. The vulnerability requires the NO_BACKSLASH_ESCAPES mode to be enabled and affects text-protocol escaping functions.
Mitigation Recommendations
Upgrade MariaDB Connector/Node.js to version 3.2.5, 3.3.4, 3.4.7, or 3.5.4 or later, where this issue is fixed. Avoid using text-protocol escaping with NO_BACKSLASH_ESCAPES mode enabled in vulnerable versions. Use execute() and batch() methods which use binary protocols and are not affected by this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-07T21:07:54.988Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac7fef32cdf04f656318c11
Added to database: 10/08/2026, 20:37:07 UTC
Last enriched: 10/08/2026, 20:48:34 UTC
Last updated: 10/08/2026, 21:45:49 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.