Vulnerability GHSA-v6pj-gxxw-phfw

High Risk
HIGH RISK
CVSS Score: 8.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 hours ago
October 08, 2026 at 07:42 PM UTC
MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)
3.2.0 - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3
3.2.0 - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3

Summary

MariaDB Connector/Node.js: SQL injection through object keys in SET expansion (permitSetMultiParamEntries)

Details

Description

With the non-default permitSetMultiParamEntries option enabled, an object passed as a query parameter is expanded into a SET clause, each key becoming a column name. The three code paths implementing that expansion built the backtick-quoted identifier by hand and wrote the key out unescaped, while only the value was escaped.

A key containing a backtick therefore closed the identifier, and the remainder of the key was parsed as SQL. The connector's own identifier escaper (escapeId, which correctly doubles backticks) existed but was not called from any of the three sites. This is an incomplete fix of GitHub issue #252, which corrected escapeId itself in 2023 but left these hand-built call sites unchanged.

Impact

An application that enables permitSetMultiParamEntries and passes an object with attacker-influenced keys into a statement such as conn.query('UPDATE users SET ? WHERE id = ?', [body, id]) allows the caller to write columns the application never intended to expose — a role, balance or password column — and to append arbitrary SQL to the statement, since the injected text is not confined to an assignment.

Exposure requires the option to be enabled: it is off by default, and with it off the object is serialised and escaped as a single string literal, so the key never reaches the SQL grammar. Passing a request body into this API is, however, the ordinary reason to enable the option. An application that enables it is asking for keys to become column names, not for keys to become arbitrary SQL.

Resolution

All three expansion sites now route the key through the identifier escaper, doubling backticks before writing the column name. The feature is unchanged for legitimate keys, including reserved words.

Workarounds

Disable permitSetMultiParamEntries (the default), or validate object keys against an allow-list of column names before passing them to query(), until upgraded.

Credit

Reported by fg0x0.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
3 hours ago
MariaDB Connector/Node.js: SQL injection in the text protocol when the session uses NO_BACKSLASH_ESCAPES
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3 GHSA-r3rv-jm3r-62q2
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3 GHSA-r3rv-jm3r-62q2
High Risk
3 hours ago
MariaDB Connector/Node.js exposes uninitialized process memory through malformed GeoJSON parameters
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3 GHSA-48qf-xh34-q73r
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.3 GHSA-48qf-xh34-q73r
Medium Risk
3 hours ago
MariaDB Connector/Node.js: Uncaught exception crashes the client during ed25519 authentication with zero-configuration TLS
3.3.0 - 3.5.3 GHSA-cx2f-j9fh-8g68
3.3.0 - 3.5.3 GHSA-cx2f-j9fh-8g68
Medium Risk
1 month ago
MariaDB has possible SQL injection in Buffer parameter escaping under big5/gbk/sjis/cp932/gb18030 client charsets
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.2 GHSA-g5xc-5w98-jfvm
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.2 GHSA-g5xc-5w98-jfvm
Medium Risk
1 month ago
MariaDB has Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.2 GHSA-42r5-vhpq-m858
0.0.1-security - 3.2.3 and 3.3.0 - 3.3.2 and 3.4.0 - 3.4.5 and 3.5.1 - 3.5.2 GHSA-42r5-vhpq-m858
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
3 hours ago
October 08, 2026 at 07:42 PM UTC
Fixed (3.5.4)
1 month ago
September 01, 2026 at 04:38 PM UTC
Fixed (3.3.4)
1 month ago
September 01, 2026 at 04:41 PM UTC
Fixed (3.2.5)
Unknown
Unknown
Fixed (3.4.7)
Unknown
Unknown
Last Modified
3 hours ago
October 08, 2026 at 08:00 PM UTC