MariaDB Connector/Nodejs, SQL Injection, CVE-2026-107384 (High) -DC-Oct2026-2951

Listen to this Post

MariaDB Connector/Node.js contains a vulnerability related to SQL injection during SET clause expansion when the non-default permitSetMultiParamEntries option is enabled. When an application passes an object as a query parameter, each key is expanded into a column name for a SQL SET clause. The internal code paths build the backtick-quoted identifier manually by writing the key out unescaped while only escaping the associated value. Because the key itself lacks proper identifier escaping, an attacker who can influence the object keys can supply a backtick character to prematurely close the identifier context. Any text following the backtick is then parsed directly as raw SQL commands rather than being treated as a safe column identifier. This flaw represents an incomplete implementation fix for a prior issue where the connector’s identifier escaper function was corrected but not invoked across these specific hand-built query expansion sites, allowing malicious inputs to manipulate database records or append arbitrary SQL code statements.

DailyCVE Form:

Platform: MariaDB Connector/Node.js
Version: < 3.5.4
Vulnerability : SQL Injection
Severity: High
date: 2026-08-10

Prediction: 2026-08-10

What Undercode Say:

Analytics

The vulnerability stems from manual string concatenation used to construct backtick-quoted identifiers within query parameter expansion paths. Specifically, the connector failed to invoke its built-in identifier escape mechanism (escapeId) on object keys when processing query inputs under the `permitSetMultiParamEntries` configuration.

Exploit: (Educational Purposes!)

const exploitPayload = {
"` = 1; DROP TABLE users; --": "value"
};
conn.query('UPDATE users SET ? WHERE id = ?', [exploitPayload, 1]);

Protection: from this CVE

To protect against this vulnerability, upgrade MariaDB Connector/Node.js to version 3.5.4 or later where object keys are correctly routed through the identifier escaper. Alternatively, keep the `permitSetMultiParamEntries` option disabled by default or implement strict whitelist validation on object keys before passing them into query statements.

Impact

An attacker capable of controlling or influencing object keys passed into database operations with `permitSetMultiParamEntries` enabled can write to confidential or restricted columns—such as user roles, account balances, or credentials—and inject arbitrary SQL statements, leading to full database compromise or data manipulation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top