CVE-2026-107384
Last modified
CVE-2026-107384 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId.
Description
MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. From 3.2.0 until 3.2.5, 3.3.4, 3.4.7, and 3.5.4, applications that enable permitSetMultiParamEntries can pass objects whose keys are expanded into a SQL SET clause without being processed by escapeId. An attacker-controlled key containing a backtick can close the quoted identifier and cause the remainder of the key to be interpreted as SQL. This can update columns the application did not intend to expose and can append arbitrary SQL with the database user's privileges. The option is disabled by default, and serialized-object handling used when it is disabled is not affected. This issue is fixed in versions 3.2.5, 3.3.4, 3.4.7, and 3.5.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| mariadb-corporation | mariadb-connector-nodejs | >= 3.2.0, < 3.2.5; >= 3.3.0, < 3.3.4; >= 3.4.0, < 3.4.7; >= 3.5.0-rc.0, < 3.5.4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107384?
How severe is CVE-2026-107384?
How do I fix CVE-2026-107384?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107378CairoSVG is an SVG converter based on Cairo, a 2D graphics l…8.7
- CVE-2026-107379savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, s…6.5
- CVE-2026-10738The jQuery Hover Footnotes plugin for WordPress is vulnerabl…6.4
- CVE-2026-107380savg-sanitizer is a PHP SVG/XML sanitizer. Prior to 1.0.0, s…5.4
- CVE-2026-107382MariaDB Connector/Node.js is used to connect applications de…5.9
- CVE-2026-107383MariaDB Connector/Node.js is used to connect applications de…7.5
- CVE-2026-107385MariaDB Connector/Node.js is used to connect applications de…7.4
- CVE-2026-107386amqp091-go is a Go AMQP 0.9.1 client. From 1.13.0 until 1.14…6.3
- CVE-2026-107387music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-107388music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-107389music-metadata is a metadata parser for audio and video medi…6.2
- CVE-2026-10739Cato Networks SDP Client for Windows before 6.12.6 allows a …8.5
Are you affected by CVE-2026-107384?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
