Medium · 4.9 Node.js & npm GHSA-r3rv-jm3r-62q2 CVE-2026-107385
CVE-2026-107385
MariaDB Connector/Node.js text-protocol escaping ignores NO_BACKSLASH_ESCAPES, allowing SQL injection via Connection.escape() and other text-protocol paths. Fixed in vendor updates.
AI summary
A bug in MariaDB Connector/Node.js causes text-protocol escaping to always prefix quotes with a backslash and ignore the session sql_mode NO_BACKSLASH_ESCAPES. When that mode is in effect, an attacker-controlled placeholder can close a string literal and inject SQL. The issue is tracked as CVE-2026-107385 and has fixes available.
What happened
MariaDB Connector/Node.js's text-protocol escaping always prefixes quotes with a backslash and does not honor the session sql_mode NO_BACKSLASH_ESCAPES, including in Connection.escape(). When NO_BACKSLASH_ESCAPES is enabled the backslash is an ordinary character, so an attacker-controlled placeholder value can close a SQL string literal and inject arbitrary SQL executed with the application's database privileges. Execute() and batch() use the binary protocol and are not affected. (Sources: 4108, 31885)
Technical cause
The connector's text-protocol escaping logic unconditionally prefixes quotes with a backslash and therefore does not respect the server session mode NO_BACKSLASH_ESCAPES. That mismatch between escaping behavior and the server's string-escaping rules permits crafted placeholder values to terminate string literals and inject SQL. Binary-protocol paths (execute() and batch()) are not affected. (Source: 4108)
Why it matters
Successful exploitation allows an attacker to inject arbitrary SQL that runs with the application's database privileges, creating high integrity and availability impact. The advisory's CVSS 3.1 vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H and the base score is 7.4. The advisory notes no known public exploit and no recorded known exploitation. (Sources: 31885, 4108)
Who is affected
Applications that use the mariadb npm package (MariaDB Connector/Node.js) and that either enable NO_BACKSLASH_ESCAPES server-side or set that sql_mode for a session, and that use the connector's text-protocol escaping (for example Connection.escape()), are affected. Binary-protocol usage via execute() or batch() is not vulnerable. (Source: 4108)
Discovery and timeline
The issue is published in the OSV and NVD records for CVE-2026-107385. The OSV entry was published 2026-10-08 and the NVD entry published 2026-10-08; the advisory record lists last modification on 2026-10-09. (Sources: 4108, 31885)
Affected versions
The advisory lists multiple affected ranges and fixed releases for the mariadb npm package. Fixed releases are 3.2.5, 3.3.4, 3.4.7 and 3.5.4. The published affected ranges in the advisory are: - 0 up to (but not including) 3.2.5 - 3.3.0 up to (but not including) 3.3.4 - 3.4.0 up to (but not including) 3.4.7 - 3.5.0-rc.0 up to (but not including) 3.5.4 Check your installed mariadb package against these ranges and the fixed releases. (Source: 4108)
Fixes and mitigation
The connector is fixed in the vendor updates listed above (3.2.5, 3.3.4, 3.4.7 and 3.5.4). As noted in the advisory, using binary-protocol paths such as execute() and batch() is not affected. There is no public exploit recorded in the advisory. (Source: 4108)
Recommended action
Where possible, upgrade the mariadb npm package to one of the fixed releases (3.2.5, 3.3.4, 3.4.7 or 3.5.4) as appropriate for your dependency line. If you cannot update immediately, review whether your application uses Connection.escape() or other text-protocol escaping while a session runs with NO_BACKSLASH_ESCAPES enabled, and consider using binary-protocol methods (execute(), batch()) where feasible. Verify the behavior in a test environment before deploying. (Source: 4108)
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
Why this score
The advisory's CVSS 3.1 base score is 7.4 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H), indicating a network attack vector, no privileges required, and high integrity and availability impact. Patchwire score is 4.9; contributing factors in the advisory include the CVSS base (contribution 4.07), the fact that the vulnerability can be triggered without authentication (unauthenticated_remote, contribution 0.6), and that it requires no user interaction (no_user_interaction, contribution 0.2). The advisory records no known exploitation or public exploit. (Sources: 31885, 4108)
Affected versions
- mariadb ≥ 3.5.0-rc.0 < 3.5.4
- vulnerable
- ≥ 3.2.5
- patched
- ≥ 3.3.4
- patched
- ≥ 3.4.7
- patched
- ≥ 3.5.4
- patched
Reported fixes
The connector is fixed in the vendor updates listed above (3.2.5, 3.3.4, 3.4.7 and 3.5.4). As noted in the advisory, using binary-protocol paths such as execute() and batch() is not affected. There is no public exploit recorded in the advisory. (Source: 4108)
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email