Impact
MariaDB Connector/Node.js contains a flaw where the text protocol escape logic always prefixes quotes with a backslash and ignores the NO_BACKSLASH_ESCAPES session setting. When that mode is enabled, the backslash ceases to be an escape character, allowing an attacker to close an SQL string literal and inject arbitrary SQL statements that run under the database user the application uses. This flaw can lead to unintended data disclosure, modification, or deletion, and can result in elevated privileges on the database if the application runs with elevated database rights. The vulnerability is inherent to the connector’s escape handling (CWE‑89).
Affected Systems
The issue affects MariaDB Corporation’s MariaDB Connector/Node.js used by Node.js applications to connect to MariaDB or MySQL databases. All releases before 3.2.5, 3.3.4, 3.4.7, or 3.5.4 are vulnerable; the fix is included in those four releases. The problem only occurs when the session uses the NO_BACKSLASH_ESCAPES SQL mode; binary protocol calls such as execute() and batch() are safe. Any application that constructs dynamic SQL without sanitizing input and passes values through Connection.escape() is potentially exposed.
Risk and Exploitability
The CVSS score is 7.4, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying there is no public exploit yet, but the flaw remains exploitable by an attacker with access to supply input to the vulnerable connector. Attackers can exploit the flaw remotely through the application’s input handling, and the vulnerability is easier to exploit when the database session is configured to use NO_BACKSLASH_ESCAPES. Because the issue is in client‑side escape logic, it requires the application’s code to be affected, but an attacker can simply craft input that slides through the escape routine and inject SQL. The only remediation is to upgrade or reconfigure the connector to ignore the mode.
OpenCVE Enrichment
Github GHSA