Medium · 5.3 Node.js & npm GHSA-v6pj-gxxw-phfw CVE-2026-107384
CVE-2026-107384: SQL injection via object keys in MariaDB Connector/Node.js SET expansion
MariaDB Connector/Node.js contains an SQL injection vulnerability (CWE-89) when the permitSetMultiParamEntries option is enabled. Malicious object keys can close quoted identifiers and inject SQL. Fixed in vendor updates. [source: 4110, 31884]
AI summary
This advisory covers CVE-2026-107384 in MariaDB Connector/Node.js. The connector can expand object keys into a SQL SET clause; when the permitSetMultiParamEntries option is enabled, those keys are not processed by escapeId and a backtick in a key can break the quoted identifier and inject SQL. The issue is documented by OSV and NVD. [source: 4110, 31884]
What happened
MariaDB Connector/Node.js allows object keys to be expanded into SQL SET clauses. When the permitSetMultiParamEntries option is enabled, keys are not run through escapeId; an attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder to be interpreted as SQL. This can update columns the application did not intend to expose or append arbitrary SQL executed with the database user's privileges. The issue is tracked as CVE-2026-107384 and classified as SQL injection (CWE-89). [source: 4110, 31884]
Technical cause
The connector expands object keys directly into a SET clause without applying escapeId when permitSetMultiParamEntries is enabled. A key that includes a backtick can terminate the quoted identifier and allow the rest of the key string to be parsed as SQL, leading to injection. Serialized-object handling used when the option is disabled is not affected. [source: 4110, 31884]
Why it matters
Successful exploitation can let an attacker update columns the application intended to protect and append arbitrary SQL statements executed with the same privileges as the database account used by the application. The connector runs in application code, so injection can occur remotely from the application layer when the vulnerable option is enabled. [source: 4110, 31884]
Who is affected
Applications that use MariaDB Connector/Node.js and have enabled the permitSetMultiParamEntries option are affected. The permitSetMultiParamEntries option is disabled by default; code paths that rely on the default serialized-object behavior are not affected. [source: 4110, 31884]
Affected versions
The advisory identifies multiple affected series. OSV's published data lists these introduced/fixed events: introduced in 3.2.0 and fixed in 3.2.5; introduced in 3.3.0 and fixed in 3.3.4; introduced in 3.4.0 and fixed in 3.4.7; and introduced in 3.5.0-rc.0 and fixed in 3.5.4. See vendor releases for exact upgrade targets. [source: 4110]
Fixes and mitigation
A vendor update is available that addresses the issue. Fixed releases listed by the vendor are 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot update immediately, ensure that permitSetMultiParamEntries is not enabled in your deployment; the default serialized-object handling is not affected. [source: 4110]
Recommended action
1) Upgrade Connector/Node.js to one of the vendor fixed releases (3.2.5, 3.3.4, 3.4.7 or 3.5.4) as appropriate for your distribution. 2) If upgrading is not possible immediately, verify that permitSetMultiParamEntries is disabled in your configuration and avoid enabling it until you have applied the vendor update. 3) Review database-facing code and audit any use of multi-parameter SET expansion for unexpected exposure of columns. [source: 4110]
Discovery and timeline
The vulnerability was published in public vulnerability databases on 2026-10-08; the advisory metadata includes a publish timestamp of 2026-10-08 and a modification on 2026-10-09. See the referenced OSV and NVD entries for the original notices. [source: 4110, 31884]
PatchBriefing score
5.3 / 10 · Medium
Official CVSS: 8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Why this score
CVSS v3.1 base score 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates a high-severity remote injection vulnerability that can impact confidentiality, integrity and availability. Patchwire score 5.3 factors the CVSS base and additional context (unauthenticated remote attack path and no user interaction required) to prioritize action. [source: 31884]
Affected versions
- mariadb ≥ 3.5.0-rc.0 < 3.5.4
- vulnerable
- ≥ 3.2.5
- patched
- ≥ 3.3.4
- patched
- ≥ 3.4.7
- patched
- ≥ 3.5.4
- patched
Reported fixes
A vendor update is available that addresses the issue. Fixed releases listed by the vendor are 3.2.5, 3.3.4, 3.4.7 and 3.5.4. If you cannot update immediately, ensure that permitSetMultiParamEntries is not enabled in your deployment; the default serialized-object handling is not affected. [source: 4110]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email