Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Published: 2026-10-08
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: Arbitrary SQL Execution
Action: Patch Connector
AI Analysis

Impact

MariaDB Connector/Node.js contains a flaw where the text protocol escape logic always prefixes quotes with a backslash and ignores the NO_BACKSLASH_ESCAPES session setting. When that mode is enabled, the backslash ceases to be an escape character, allowing an attacker to close an SQL string literal and inject arbitrary SQL statements that run under the database user the application uses. This flaw can lead to unintended data disclosure, modification, or deletion, and can result in elevated privileges on the database if the application runs with elevated database rights. The vulnerability is inherent to the connector’s escape handling (CWE‑89).

Affected Systems

The issue affects MariaDB Corporation’s MariaDB Connector/Node.js used by Node.js applications to connect to MariaDB or MySQL databases. All releases before 3.2.5, 3.3.4, 3.4.7, or 3.5.4 are vulnerable; the fix is included in those four releases. The problem only occurs when the session uses the NO_BACKSLASH_ESCAPES SQL mode; binary protocol calls such as execute() and batch() are safe. Any application that constructs dynamic SQL without sanitizing input and passes values through Connection.escape() is potentially exposed.

Risk and Exploitability

The CVSS score is 7.4, indicating high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, implying there is no public exploit yet, but the flaw remains exploitable by an attacker with access to supply input to the vulnerable connector. Attackers can exploit the flaw remotely through the application’s input handling, and the vulnerability is easier to exploit when the database session is configured to use NO_BACKSLASH_ESCAPES. Because the issue is in client‑side escape logic, it requires the application’s code to be affected, but an attacker can simply craft input that slides through the escape routine and inject SQL. The only remediation is to upgrade or reconfigure the connector to ignore the mode.

Generated by OpenCVE AI on October 8, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MariaDB Connector/Node.js to version 3.2.5 or later.
  • If an upgrade cannot be performed immediately, configure the connector or the database to disable NO_BACKSLASH_ESCAPES for all text‑protocol connections or enforce strict escape handling in the application layer.
  • Ensure the application uses parameterized queries or properly sanitizes user input before passing it to the connector.

Generated by OpenCVE AI on October 8, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-r3rv-jm3r-62q2 MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
History

Thu, 08 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Mariadb
Mariadb connector-nodejs
Vendors & Products Mariadb
Mariadb connector-nodejs

Thu, 08 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.5, 3.3.4, 3.4.7, and 3.5.4, text-protocol escaping always prefixes quotes with a backslash and does not honor the session's NO_BACKSLASH_ESCAPES mode, including in Connection.escape(). When that mode is enabled, the backslash is an ordinary character, so an attacker-controlled placeholder value can close the SQL string literal and inject arbitrary SQL with the application's database privileges. The vulnerable configuration may be enabled server-wide, through connector initialization options, or with an application-issued SET sql_mode; execute() and batch() use binary protocols and are not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Title MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Mariadb Connector-nodejs
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T18:38:29.490Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107385

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:01.170

Modified: 2026-10-08T20:25:00.647

Link: CVE-2026-107385

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:15:13Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')