---
id: CVE-2026-107384
title: >-
  MariaDB Connector/Node.js is used to connect applications developed on Node.js
  to MariaDB and MySQL databases
summary: >-
  MariaDB Connector/Node.js is used to connect applications developed on Node.js
  to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and
  3.5.4, applications that enable permitSetMultiParamEntries can pass objects
  whose ke…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: mariadb
product: mariadb
affected:
  - 'mariadb >= 3.2.0, < 3.2.5'
  - 'mariadb >= 3.3.0, < 3.3.4'
  - 'mariadb >= 3.4.0, < 3.4.7'
  - 'mariadb >= 3.5.0-rc.0, < 3.5.4'
patched:
  - mariadb 3.2.5
  - mariadb 3.3.4
  - mariadb 3.4.7
  - mariadb 3.5.4
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:25:00.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107384'
references:
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/144b8f4ef29539a9fb4b75d972b9dcdac4088b4e
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/6743b2f4a89b074268b44c650170767f35e1fb5d
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/8eb450972ff0f3826d7d45c071a42240798bc826
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/commit/b9b04ec82a60b2caf2b0c038259ca9aff5d7014a
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.2.5
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.3.4
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.4.7
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/releases/tag/3.5.4
    label: security-advisories@github.com
  - url: >-
      https://github.com/mariadb-corporation/mariadb-connector-nodejs/security/advisories/GHSA-v6pj-gxxw-phfw
    label: security-advisories@github.com
  - url: 'https://hackerone.com/reports/3889198'
    label: security-advisories@github.com
  - url: 'https://jira.mariadb.org/browse/CONJS-369'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-v6pj-gxxw-phfw'
tags:
  - nvd
  - ghsa
  - npm
aliases:
  - GHSA-v6pj-gxxw-phfw
ecosystem: npm
ingestedAt: '2026-10-08T20:06:22.186Z'
---

## Overview

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107384)

Affected packages:

- `mariadb >= 3.2.0, < 3.2.5`
- `mariadb >= 3.3.0, < 3.3.4`
- `mariadb >= 3.4.0, < 3.4.7`
- `mariadb >= 3.5.0-rc.0, < 3.5.4`

Patched in:

- `mariadb 3.2.5`
- `mariadb 3.3.4`
- `mariadb 3.4.7`
- `mariadb 3.5.4`

Source: https://github.com/advisories/GHSA-v6pj-gxxw-phfw
