Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.9 Node.js & npm GHSA-r3rv-jm3r-62q2 CVE-2026-107385

CVE-2026-107385

MariaDB Connector/Node.js text-protocol escaping ignores NO_BACKSLASH_ESCAPES, allowing SQL injection via Connection.escape() and other text-protocol paths. Fixed in vendor updates.

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A bug in MariaDB Connector/Node.js causes text-protocol escaping to always prefix quotes with a backslash and ignore the session sql_mode NO_BACKSLASH_ESCAPES. When that mode is in effect, an attacker-controlled placeholder can close a string literal and inject SQL. The issue is tracked as CVE-2026-107385 and has fixes available.

What happened

MariaDB Connector/Node.js's text-protocol escaping always prefixes quotes with a backslash and does not honor the session sql_mode NO_BACKSLASH_ESCAPES, including in Connection.escape(). When NO_BACKSLASH_ESCAPES is enabled the backslash is an ordinary character, so an attacker-controlled placeholder value can close a SQL string literal and inject arbitrary SQL executed with the application's database privileges. Execute() and batch() use the binary protocol and are not affected. (Sources: 4108, 31885)

Technical cause

The connector's text-protocol escaping logic unconditionally prefixes quotes with a backslash and therefore does not respect the server session mode NO_BACKSLASH_ESCAPES. That mismatch between escaping behavior and the server's string-escaping rules permits crafted placeholder values to terminate string literals and inject SQL. Binary-protocol paths (execute() and batch()) are not affected. (Source: 4108)

Why it matters

Successful exploitation allows an attacker to inject arbitrary SQL that runs with the application's database privileges, creating high integrity and availability impact. The advisory's CVSS 3.1 vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H and the base score is 7.4. The advisory notes no known public exploit and no recorded known exploitation. (Sources: 31885, 4108)

Who is affected

Applications that use the mariadb npm package (MariaDB Connector/Node.js) and that either enable NO_BACKSLASH_ESCAPES server-side or set that sql_mode for a session, and that use the connector's text-protocol escaping (for example Connection.escape()), are affected. Binary-protocol usage via execute() or batch() is not vulnerable. (Source: 4108)

Discovery and timeline

The issue is published in the OSV and NVD records for CVE-2026-107385. The OSV entry was published 2026-10-08 and the NVD entry published 2026-10-08; the advisory record lists last modification on 2026-10-09. (Sources: 4108, 31885)

Affected versions

The advisory lists multiple affected ranges and fixed releases for the mariadb npm package. Fixed releases are 3.2.5, 3.3.4, 3.4.7 and 3.5.4. The published affected ranges in the advisory are: - 0 up to (but not including) 3.2.5 - 3.3.0 up to (but not including) 3.3.4 - 3.4.0 up to (but not including) 3.4.7 - 3.5.0-rc.0 up to (but not including) 3.5.4 Check your installed mariadb package against these ranges and the fixed releases. (Source: 4108)

Fixes and mitigation

The connector is fixed in the vendor updates listed above (3.2.5, 3.3.4, 3.4.7 and 3.5.4). As noted in the advisory, using binary-protocol paths such as execute() and batch() is not affected. There is no public exploit recorded in the advisory. (Source: 4108)

Recommended action

Where possible, upgrade the mariadb npm package to one of the fixed releases (3.2.5, 3.3.4, 3.4.7 or 3.5.4) as appropriate for your dependency line. If you cannot update immediately, review whether your application uses Connection.escape() or other text-protocol escaping while a session runs with NO_BACKSLASH_ESCAPES enabled, and consider using binary-protocol methods (execute(), batch()) where feasible. Verify the behavior in a test environment before deploying. (Source: 4108)

PatchBriefing score

4.9 / 10 · Medium

Official CVSS: 7.4

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Why this score

The advisory's CVSS 3.1 base score is 7.4 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H), indicating a network attack vector, no privileges required, and high integrity and availability impact. Patchwire score is 4.9; contributing factors in the advisory include the CVSS base (contribution 4.07), the fact that the vulnerability can be triggered without authentication (unauthenticated_remote, contribution 0.6), and that it requires no user interaction (no_user_interaction, contribution 0.2). The advisory records no known exploitation or public exploit. (Sources: 31885, 4108)

Affected versions

mariadb ≥ 3.5.0-rc.0 < 3.5.4
vulnerable
≥ 3.2.5
patched
≥ 3.3.4
patched
≥ 3.4.7
patched
≥ 3.5.4
patched

Reported fixes

The connector is fixed in the vendor updates listed above (3.2.5, 3.3.4, 3.4.7 and 3.5.4). As noted in the advisory, using binary-protocol paths such as execute() and batch() is not affected. There is no public exploit recorded in the advisory. (Source: 4108)

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
CVE-2026-107385
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email